• IP addresses are NOT logged in this forum so there's no point asking. Please note that this forum is full of homophobes, racists, lunatics, schizophrenics & absolute nut jobs with a smattering of geniuses, Chinese chauvinists, Moderate Muslims and last but not least a couple of "know-it-alls" constantly sprouting their dubious wisdom. If you believe that content generated by unsavory characters might cause you offense PLEASE LEAVE NOW! Sammyboy Admin and Staff are not responsible for your hurt feelings should you choose to read any of the content here.

    The OTHER forum is HERE so please stop asking.

Unholy Hong Kong hackers hit evangelicals with IE 0day

AnonOps

Alfrescian
Loyal
Joined
Dec 19, 2014
Messages
184
Points
0

Unholy Hong Kong hackers hit evangelicals with IE 0day

Fast moving blackhats backdoor church-goers.

21 Aug 2015 at 03:55, Darren Pauli

ie_8233423423.jpg


Hackers are already using an Internet Explorer vulnerability disclosed this week to hack members of an evangelical church.

The attackers compromised the website of the Evangelical Lutheran Church of Hong Kong, injecting a malicious iFrame that redirects the faithful to a malicious website sporting the Internet Explorer vulnerability (CVE-2015-2502).

More javascript redirections lead to the PlugX (pdf) malware landing on machines. Once running, the malware opens a back door and begins harvesting data.

"The malware has been used in a range of attacks, mainly in Asia over the past three years," researcherssay.

"The vulnerability permits remote code execution if a user views a specially crafted webpage using Internet Explorer.

"Successful exploit of the vulnerability will grant the attacker the same user rights as the current user."

The unholy blackhats can gain unfettered access to the church-goer's computers including the ability to install programs, siphon or destroy data.

The weaponisation is impressive but not altogether unexpected; powerful browser vulnerabilities are a favourite of blackhats and they are quick to exploit it before users have time to patch.

The exploited bug is valuable because it affects all supported versions of Internet Explorer and is sufficiently dangerous that Microsoft made a rare and expensive out-of-band fix.

Users can apply the fix or move to the unaffected Microsoft Edge browser if they operate Windows 10. They should also install Microsoft's enhanced mitigation experience toolkit to increase their overall defences.


 
Back
Top