iTnews

Certificate phishing sucks bank customers into Blackhole

By Dan Raywood on Sep 19, 2011 12:50PM
Certificate phishing sucks bank customers into Blackhole

Bank business customers warned of invalid certificates.

Spammers are telling bank business customers that their SSL certificates had expired in efforts to exploit the blacklisting of certificate authority DigiNotar.

DigitNotar was blacklisted by major browsers after it was hacked and issued fraudulent certificates.

Barracuda Networks security researchers Dave Michmerhuizen and Luis Chapetti said the spam carried a dangerous message.

"The spammers try to create a sense of urgency with the hope that you will click one of the links to see what happens; which in this case is a particularly bad idea because the second link in the message directs the browser to a server hosting an exploit kit," they said.

“Once the browser visits that site a series of attacks begin which can result in the download of Trojan.Buzus."

That malware payload stole login credentials and created a backdoor that allowed remote control of compromised machines.

Barracuda said that it is seeing more overtly malicious spam directing users to malicious sites since the Blackhole exploit kit became widely available earlier this year.

Websense Security Labs security research manager Carl Leonard said it was a low volume campaign of less than 100 messages.

“It took the user to a .scr file that delivered the exploits. But this shows that scammers are tuned into the hot topics."

“This is not a targeted attack in an advanced persistent threat style, but it looks like a phishing email but this is much more sinister as it delivers an exploit kit and not a standard phish."

He also said the Blackhole exploit kit was one of the most popular kits in the wild.

Blackhole was based on PHP and a MySQL backend and targeted Windows operating systems and applications.

It also allowed a malicious payload file's name to be changed to make it undetectable by anti-virus, while exploits were encrypted with custom algorithms.

This article originally appeared at scmagazineuk.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:
certificates diginotar fraud phishing security spam

Partner Content

Beat the DDoS blackmails in 2021
Promoted Content Beat the DDoS blackmails in 2021
COVID puts agile IT under the microscope
Promoted Content COVID puts agile IT under the microscope
As Australian companies lean more heavily on the cloud, edge security is finding its stride
Partner Content As Australian companies lean more heavily on the cloud, edge security is finding its stride
What conversations should executives be having about cyber security?
Partner Content What conversations should executives be having about cyber security?

Sponsored Whitepapers

The top 5 tech trends to deliver business outcomes
The top 5 tech trends to deliver business outcomes
10 reasons why businesses need to invest in cloud security training
10 reasons why businesses need to invest in cloud security training
Your guide to application security solutions
Your guide to application security solutions
State of Software Security: Open Source Edition
State of Software Security: Open Source Edition
Five questions to ask before you upgrade to a SIEM solution
Five questions to ask before you upgrade to a SIEM solution

Events

  • On-Demand Webinar: How Poly and Microsoft are Embracing Future Work Environments
  • [iTnews and Micro Focus] Navigating the cloud modernisation minefield
By Dan Raywood
Sep 19 2011
12:50PM
0 Comments

Related Articles

  • RMIT cancels classes after IT outage
  • ATO to keep JobMaker businesses honest with data matching
  • BOQ tries to pin BEC blame on a branch manager
  • RAT scammers pose as the Australian Cyber Security Centre
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Infosys scores another $40m for Centrelink payments engine build

Infosys scores another $40m for Centrelink payments engine build

TPG Telecom to start enticing NBN customers to move

TPG Telecom to start enticing NBN customers to move

Bosch, Microsoft join forces to develop vehicle software platform

Bosch, Microsoft join forces to develop vehicle software platform

Telstra InfraCo opens up telco's own fibre network

Telstra InfraCo opens up telco's own fibre network

You must be a registered member of iTnews to post a comment.
Log In | Register
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.