Ad-based Trojan hits MySpace, Bebo and others

Malware hidden in adverts

Written by Matt Chapman

Users of high profile sites including MySpace, The Sun, Bebo and PhotoBucket have been exposed to a Trojan hidden within adverts.

The sites all ran advertising in recent weeks from the Right Media online ad exchange which were unknowingly infected with the Downloader.VBS.Agent.n Trojan.

"This is another example of how legitimate 'trusted' websites can unknowingly host malware," said Dan Nadir, vice president of product strategy at ScanSafe.

"Online ads have become a primary target for malware authors because they offer a stealthy way to distribute malware to a wide audience."

Nadir explained that the malware was particularly dangerous because it required no user interaction for infection to take place.

ScanSafe estimates that up to 12 million ads may have been delivered, exposing a large number of users to the Trojan.

The security vendor saw a surge in blocks of the Trojan beginning on 8 August and continuing until early September.

Nadir added that it will be very difficult to track down the source of the malware because the hacker used the distributed nature of online advertising to spread the code to hundreds of sites.

One of the infected adverts used a Flash file to generate an invisible iFrame. This was linked to an IP address containing obfuscated visual basic script that used the well-known MDAC exploit to download a Trojan executable.

ScanSafe believes that the malicious script inside the Flash ad avoided detection by Right Media because of the clever use of a referrer check. This meant that the advert only became active when delivered by a particular ad server.

The Downloader.VBS.Agent.n malware downloads other programs which are launched on the victim's machine without knowledge or consent.

ScanSafe said that several well known sites, including TomsHardware, have unwittingly hosted malware that was inserted via infected online ads.

See also:

reader comments

related articles

Storm worm back with a vengeance

Quarter of all detected threats during August, says BitDefender 10 Sep 2007

 

Malware-laden spam promises pop videos

Email links lead to malicious script and Trojan horse 30 Aug 2007

Web hosting firm harbours virus

Not known how far infection has spread 23 Aug 2007

Cyber-criminals unleash spam Storm

Experts warn of 'confirmation spam' outbreak 22 Aug 2007

Trojan uses Hotmail and Yahoo as spam hosts

Scammers bypassing authentication systems 06 Jul 2007

Web sites staying infected with malicious software for longer

Some sites are not being cleaned up for two months, according to research 01 Apr 2008

Pro-Tibet websites infected with Trojans

Security firm says sites deliberately targeted following Olympic torch protests 09 Apr 2008

Legitimate web sites hosting malware

"Drive-by" infections used to be the preserve of criminal sites only 25 Jan 2008

latest news

Ironport slams partner margin erosion claim

UK partner manager hails content security vendor’s acquisition by Cisco as a boon for UK resellers 09 Jan 2009

Sun sets higher bar with telemarketing budget

Vendor plans to turn its popularity among the open-source community into a revenue stream 09 Jan 2009

Novell to shuffle EMEA executive pack

Linux vendor shifts partner programme responsibilities to marketing organisation 09 Jan 2009

poll

Challenging times ahead?

Challenging times ahead?

Do you think there will be a lot of channel job cuts in 2009?

Previous poll results

Paul Anderson, Trend Micro

Vendor Q&A: Paul Anderson, Trend Micro

During this Q&A session Paul Anderson, UK country manager of Trend Micro talks about the changing threat landscape and how Trend is working with resellers in 2009

Sara Yirrell and Rick Wallis

Vendor Q&A: Rick Wallis, NEC Computers

In this exclusive vendor Q&A, Rick Wallis, UK sales director at NEC Computers talks to CRN editor Sara Yirrell about his firm’s plans for the channel.

events

Channel Expo 2009 logo

Channel Expo 2009

The UK's top reseller exhibition will return to the NEC on 20 May 2009

CRN Fight Night 2009

The channel's only white-collar boxing event is back

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

White papers

Search white papers

Top categories

Primary Navigation