Watering hole attack targets Chinese dissidents

By
Follow google news

Internet Explorer hole used to spy on activists.

Chinese news sites have been infected in a bid to compromise dissidents in the country, according to security firm FireEye.

Watering hole attack targets Chinese dissidents

The so-called watering hole attack infected news sites popular with targets. When dissidents vist the site, they would be infected with malware. 

The attack used an Internet Explorer 8 vulnerability patched this month, researchers Thoufique Haq and Yasir Khalid said, adding the bug would likely be rolled into other exploits.

"This is clearly a targeted attack on a very narrow portion of the Chinese populous," they said.

"However, since cyber attackers are quick copycats, we expect this exploit to be replicated quickly."

They said the attack resembled a watering hole attack launched late last year against the website for the policy think tank Council on Foreign Relations, the influential membership group that helps shape USforeign policy.

In December, the site was hijacked with malicious JavaScript to serve an Adobe Flash exploit, which in turn triggered a heap-spray attack, according to researchers at security firm FireEye.

The malware was delivered to users whose operating system language was set to English, Chinese, Japanese, Korean or Russian.

This article originally appeared at scmagazineus.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

The BoM has finally tamed SSL

The BoM has finally tamed SSL

Commercial spyware targeted Samsung Galaxy users for months

Commercial spyware targeted Samsung Galaxy users for months

US prosecutors say cyber security pros ran cybercrime operation

US prosecutors say cyber security pros ran cybercrime operation

Westpac factors post-quantum cryptography prep into "secure router" rollout

Westpac factors post-quantum cryptography prep into "secure router" rollout

Log In

  |  Forgot your password?