Mass Injection Attack Affects 40,000 WebsitesJune 2, 2009 – 12:13 PM
Researchers at Websense have discovered a mass injection attack that is redirecting Web browsers to a malware-bearing site.
“The active exploit site uses a name similar to the legitimate Google Analytics domain (google-analytics.com), which provides statistical services to Web sites,” the report says. “This mass injection attack does not seem related to Gumblar. The location of the injection, as well as the decoded code itself, seem to indicate a new, unrelated, mass injection campaign.”
The report indicates the exploit had infected some 20,000 sites, but researchers this afternoon told reporters the figure is now closer to 40,000.
Like Gumblar, the attack redirects users who conduct searches on popular Websites and search terms. The browsers are routed through a statistical server and then onto the Beladen.net site, a well-known carrier of malware.