Websites of energy sector companies compromised in watering hole attack
Posted on 20 September 2013.
Bookmark and Share
The websites of nearly a dozen energy sector companies have been compromised to serve as so-called "watering holes", where visitors would be served with malware or from which they would be redirected to other web pages where the same thing would happen.


According to Cisco researchers, who have been observing the attack since early May, among the ten websites that have been injected with the malicious iframe used in the campaign, one belongs to an oil and gas exploration firm with operations in Africa, Morocco, and Brazil; one to a gas distributor located in France; one to a natural gas power station in the UK; and several investment and capital firms that specialize in the energy sector.

Nearly half of the visitors to these sites come from the financial and energy sectors.

"Interestingly, six of the ten iframe-injected websites were hosted on the same server, apparently services by the same web design firm. Three of these six were also owned by the same parent company," pointed out Cisco's Emmanuel Tacheau. "This is likely indication the sites were compromised via stolen login credentials, possibly a result of infection with the design firm or their hosting provider."

The malware is hosted on the pages of three compromised websites (keeleux.com, kenzhebek.com, and nahoonservices.com), and to install it on the victims' computers the attackers have leveraged exploit code for vulnerabilities in older versions of Java, Internet Explorer, and Firefox / Thunderbird.

Tacheau doesn't say whether the campaign is ongoing, but he pointed out that as time went by, the attackers have modified the injected iframes, exploit code, and the served malware.

"Protecting users against these attacks involves keeping machines and web browsers fully patched to minimize the number of vulnerabilities that an attacker can exploit," he pointed out, adding that a web traffic filtering solution deployed at the the network level can block malicious content before it can reach the intended targets' machines.









Spotlight

Attackers use reflection techniques for larger DDoS attacks

Posted on 17 April 2014.  |  Instead of using a network of zombie computers, newer DDoS toolkits abuse Internet protocols that are available on open or vulnerable servers and devices. This approach can lead to the Internet becoming a ready-to-use botnet for malicious actors.


Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.
  



Daily digest

Receive a daily digest of the latest security news.
  

DON'T
MISS

Fri, Apr 18th
    COPYRIGHT 1998-2014 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //