New hacker scheme is infecting educational servers worldwide with Viagra ads
As an example of this ‘industrial revolution’, Imperva has discovered a new hacker scheme that is infecting educational servers worldwide with Viagra ads that infect web users with malware when they visit the infected page on the legitimate education site. According to Imperva, cyber-criminals are using industrialized methods to automate an as-yet unreported search engine manipulation scheme that has infected hundreds, possibly thousands of .edu and .ac.uk servers worldwide with Viagra ads.
“This attack on academic institutions highlights how hacking has become industrialized infecting servers from major institutions including UC Berkeley, Ohio State, University of Oxford and more. Ironically, this technique is the most prevalent method used to create havoc in cyberspace, yet remains virtually unknown to the general public,” explained Imperva CTO Amichai Shulman.
Key findings in the report include the organizational structure and technical innovations for automating attacks:
Organization structure
Over the years, a clear definition of roles and responsibilities within the hacking community has developed to form a supply chain that resembles a drug cartel. The division of labor in today’s industrialized hacking industry includes:
- Researchers: A researcher’s sole responsibility is to hunt for vulnerabilities in applications, frameworks, and products and feed their knowledge to malicious organizations for the sake of profit.
- Farmers: A farmer’s primary responsibility is to maintain and increase the presence of botnets in cyberspace through mass infection.
- Dealers: Dealers are tasked with the distribution of malicious payloads.
Technical innovations
Hacking techniques once considered cutting-edge and executed only by savvy experts are now bundled into software tools available for download. Today, the hacking community typically deploys a two-stage process designed to proliferate botnets and perform mass attacks.
- Search engine manipulation. This technique is the most prevalent method used to spread bots, yet remains virtually unknown to the general public. Essentially, attackers promote Web-link references to infected pages by leaving comment spam in online forums and by infecting legitimate sites with hidden references to infected pages. For example, a hacker may infect unsuspecting Web pages with invisible references to popular search terms, such as “Britney Spears” or “Tiger Woods.” Search engines then scour the websites reading the invisible references. As a result, these malicious websites now top search engine results. In turn, consumers unknowingly visit these sites and consequently infected their computers with the botnet software.
- Executing mass attacks through automated software. To gain unauthorized access into applications, dealers input email addresses and usernames as well as upload lists of anonymous proxy addresses into specialized software, the same way consumers upload addresses to distribute holiday cards. Automated attack software then performs a password attack by entering commonly used passwords. In addition, today’s industrialized hackers can also input a range of URLs and obtain inadequately protected sensitive data.
Print version |
Email to a friend |
View other articles
Latest IT, computer and network security articles
Google delivers twice the amount of malware than Twitter, Yahoo and Bing combined
Active Dashboards software gives VSG a complete picture of key operational activities
Cloudmark's Cloudfilter protects Digiweb's customers from spam
Imperva partners with NEON to provide database activity monitoring for mainframe users
Lanner releases FW-7535 network application platform for secure network communication applications
Secure data management is the healthcare industry's most pressing issue
...[view more IT, computer and network security articles]...
Other IT, computer and network security Resources
Security websites for specific products:
Access control and RFID systems - Burglar alarm, intruder alarm and fire alarm systems - Biometric recognition and identification systems - CCTV cameras and systems - IT, computer and network security systems - Health and safety - Security guard services - Surveillance and remote monitoring systems
Security websites for specific markets:
Bank and financial security - Corporate security - School and education security - Sport event and live venue security - Healthcare and hospital security - Hotel restaurant and casino security - Industrial and manufacturing security - Infrastructure and Utilities security - Home and personal security - Public sector security - Retail security - Small Business security - Transport security

