Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Spam Reports

September 19th, 2011, 07:36 GMT · By Eduard Kovacs

Rogue Certificates Used in Spam Campaigns

SHARE:

Adjust text size:


Blak hole
Enlarge picture
After the scandal formed around DigiNotar, spammers send bank business clients emails informing them that their certificates have expired, urging them to click on a link in order to solve the issue.

Most internet browsers and applications banned DigiNotar certificates, a fact which created a lot of confusion and gave internauts a sense of insecurity.

According to SC Magazine, numerous security researchers discovered a series of emails which tried to fool unsuspecting users into thinking something is wrong with their certificates, thus making them access a website that should fix their problem.

When a link was clicked, a page containing an exploit kit was accessed and the system became completely compromised.

“Once the browser visits that site a series of attacks begin which can result in the download of Trojan.Buzus," revealed a couple of Barracuda Networks security researchers.

In the monitoring period in which they kept a close watch on that virus, they realized that besides stealing log-in information, the malware also opened a backdoor, giving hackers access to the infected device.

As Carl Leonard from Websense Security Labs mentions, it looks like this Blackhole exploit kit hasn't been used a lot, the more worrying aspect being the fact that the results of this campaign can be devastating.

He explained that the threat consists of a .scr file which delivers the exploits, also stating that “This is not a targeted attack in an advanced persistent threat style, but it looks like a phishing email but this is much more sinister as it delivers an exploit kit and not a standard phish."

Blackhole seems to be one of cybercriminals' favorite exploit kits, attacking Windows based systems by using a PHP and a MySQL code to cause damage and steal information.

The worst thing about this piece of malware is that it's hard to detect by anti-virus applications because it's able to change the name of the file containing it.

TELL US WHAT YOU THINK:

1,057 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Rogue Google SSL Certificate Found in the Wild

ComodoHacker Responsible for DigiNotar Rogue Certificates

Hundreds of Rogue Certificates Possibly Issued by DigiNotar

ComodoHacker Denies That the Iranian Government Is Funding Him

GlobalSign Back on Track After ComodoHacker Threat

READER COMMENTS:


Comment #1 by: DebbieC on 19 Sep 2011, 22:26 UTC reply to this comment

Would be good to add suggested ways to address this, or to check your systems to look for and remove the exploits). - Debbie Christofferson

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM