Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Virus alerts

May 2nd, 2012, 12:12 GMT · By

Israeli Institute for National Security Studies Serves Visitors Poison Ivy RAT

SHARE:

Adjust text size:

INSS website hijacked by cybercriminals
Enlarge picture
It’s well known in the security community that Israeli websites have been under constant attack in the past few months. One of these attacks seems to have targeted the Institute for National Security Studies (INSS), whose website has been altered to serve visitors the infamous remote administration tool (RAT) known as Poison Ivy.

Websense experts found that the infection leverages the same Java exploit vector that’s currently used by the Flashback Trojan to spread on Mac OS X machines.

The INSS is an independent organization that studies Middle Eastern issues and Israel’s national security. This is what leads experts to believe that the INSS site may not be a random target, but one that’s part of an operation meant to infect the computers of individuals interested in national security related topics.

The infection starts when the site’s main page is opened. The JavaScript that has been injected into the webpage loads a Java file which holds the exploit of the CVE-2012-0507 vulnerability.

The cybercriminals responsible for hijacking the site deployed a number of methods designed to ensure that security products and malware analysis technologies would not raise any alarms when scanning the site.

To avoid being detected, they obfuscated the malicious code and they embedded a 104 megabyte text file into the Java file. The latter technique is utilized because malware scanners in many cases ignore large files, since it is known that malicious elements tend to be small in size.

Unfortunately, the site’s webmasters haven’t responded to Websense’s notification regarding the issue. That means that users who want to visit the site and don’t have the latest Java updates installed, or decent antivirus software, can almost instantly become victims.


1,649 hits
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


Russian Security Experts Analyze Backdoor.Flashback.39

Microsoft Details Mac OS X Malware That Exploits Office Vulnerability

Java-Exploiting Malware Targets Both Mac and Windows Users

Experts Present Theoretical Dangers Behind Internet-Enabled Home Appliances

Poker Forum TwoPlusTwo Shut Down Due to Breach

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM