Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

February 13th, 2013, 13:57 GMT · By

BLOG

Cybercriminals Hide Their Malicious Code by Injecting It into JavaScript

SHARE:

Adjust text size:


Malicious code injected into legitimate JavaScript code Enlarge picture - Malicious code injected into legitimate JavaScript code
Security researchers from Sophos say that cybercriminals are using a clever tactic to hide their pieces of malware on legitimate websites. They’re injecting their malware into JavaScript code that’s hosted on the site.

The malicious code inherits the reputation of the legitimate JavaScript and the main website. Even if security solutions identify the threat, the detection might be seen as a false positive.

Such techniques have been used recently to plant the Troj/iframe-JG Trojan on various legitimate websites, including the ones of a primary school from England, a London nightclub, an East African TV company, Italian community sites, and a US trade association of financial advisors.

The website of headphone manufacturer Fanny Wang has also been infected with the malware, but the company has failed to respond to the security firm’s notifications.

None of the other notified companies have responded to SophosLabs, so the experts haven’t been able to determine how the code was injected, but the hackers may have abused the fact that some of the sites are using outdated software.

TELL US WHAT YOU THINK:

2,032 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Cryptome Email, Website and Twitter Account Hacked

Sanny Malware Campaign Highly Successful in Targeting Russia, Experts Say

Cybersecurity Compliance and Best Practices Are Not the Same, Experts Warn

Valentine’s Day Cyber Scams: eCards, Chatbots and Fraudulent Stores – Video

Citi Group Customers Warned About Fake Malware-Spreading Secure Messages

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM