Crippling malware attack strikes in Italy

Researchers claim hundreds of sites compromised

Written by Shaun Nichols in California

Italy is suffering from a barrage of remote attacks launched from hundreds of compromised websites, security experts have warned.

Researchers at Symantec reported that attackers have injected 'iframe' tags within the HTML files on compromised sites.

The tags redirect users to a site that runs MPack, a utility that attempts multiple exploits and malware installations. 

More than 65,000 users had been redirected to the malicious page since Friday afternoon, and more than 7,000 successful exploits had been carried out.

Symantec researcher Elia Florio warned in a company blog that users should update antivirus software and all system and third-party software that can be vulnerable to attacks. 

Florio warned that MPack attempts to exploit multiple vulnerabilities and applications, including flaws in QuickTime and WinZip.

A successful exploit allows attackers to install malicious components such as key-loggers and password stealers.

MPack is a piece of commercial malware that includes support for plug-ins and a year of free technical support.

A May report by Panda Labs found the application selling for between $700 and $1,000, with additional exploit modules for $50 to $150.

See also:

reader comments

related articles

 

Apple QuickTime exploit goes wild

Streaming media flaw used to push malware 04 Dec 2007

QuickTime flaw adds to Apple's woes

Exploit especially dangerous for Firefox users 27 Nov 2007

vnunet.com analysis: Browser wars changing security game

Variety and competition bring new protections and new threats 18 Jun 2008

latest news

Red Hat a good fit for Qumranet

Open source behemoth opens up Windows opportunities with acquisition of virtualisation specialist 05 Sep 2008

Infor praises partners

Software vendor outlines its channel vision at second annual EMEA partner summit in Marbella 05 Sep 2008

Version One and Accurate launch university push

Software vendors link arms to create integrated document and financial management offering for universities 05 Sep 2008

Most commented stories

poll

Stormy times ahead for PBX?

Stormy times ahead for PBX?

Will the credit crunch affect PBX takeup?

Previous poll results

In The Studio With CRN: Josh Claman, Dell

In an editorial coup for CRN, Josh Claman, vice president of EMEA channels at Dell, talks to CRN TV about the vendor's channel plans

CRN Fight Night bouts are LIVE!

ALL the bouts from CRN's first ever white collar boxing event at The Brewery in Chiswell Street, are now online in their full glory for CRN readers to watch.

events

CRN Golf Challenge 2008

CRN Channel Golf Challenge 2008

CRN's annual golfing day will this year be held on 16 September at a championship course in East Sussex

CRN Reseller Leadership Forum logo

CRN Reseller Leadership Forum

An exclusive channel conference from CRN, to be held over one action-packed day in September 2008

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

White papers

Search white papers

Top categories