Mass Injection Attack Affects 40,000 Websites

June 2, 2009 – 12:13 PM

Researchers at Websense have discovered a mass injection attack that is redirecting Web browsers to a malware-bearing site.

According to a weekend report by researchers at Websense, thousands of legitimate Web sites have been discovered to be injected with malicious Javascript, obfuscated code that leads to an active exploit site.

“The active exploit site uses a name similar to the legitimate Google Analytics domain (google-analytics.com), which provides statistical services to Web sites,” the report says. “This mass injection attack does not seem related to Gumblar. The location of the injection, as well as the decoded code itself, seem to indicate a new, unrelated, mass injection campaign.”

The report indicates the exploit had infected some 20,000 sites, but researchers this afternoon told reporters the figure is now closer to 40,000.

Like Gumblar, the attack redirects users who conduct searches on popular Websites and search terms. The browsers are routed through a statistical server and then onto the Beladen.net site, a well-known carrier of malware.

Source:
http://darkreading.com/security/attacks/showArticle.jhtml?articleID=217701136

You must be logged in to post a comment.