NBC website serving malware - stay away!
Posted on 21.02.2013
Bookmark and Share
NBC's website has been compromised, and is redirecting users to malicious sites, reports Dancho Danchev.


According to HitmanPro, the website has been injected with malicious iFrames that lead to one of several compromised sites equipped with Java and PDF exploits.

It seems that upon successful exploitation of one of the vulnerabilities, the users are saddled with variants of the Citadel info-stealing Trojan that currently aren't detected by many AV solutions.

The server with which the malware communicates has already been sinkholed. Nevertheless, if you have visited the news outlet's website today, and your AV hasn't picked up on anything, use a new one to double check - preferably one of these that at the moment do.

Visiting the NBC's website is, for the time being, still dangerous, and even Facebook has moved to protect its users by not allowing the posting of the site's URL.

Danchev has tied the campaign with two previous email ones that impersonated Facebook and Verizon.

UPDATE: NBC has announced that their main website and the other web properties that have been injected with the malicious iFrames have been cleaned.










Spotlight

Is it time to professionalize information security?

Posted on 23 May 2013.  |  The issue of whether or not information security professionals should be licensed to practice has already been the topic of many a passionate debate.


Daily digest

By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
  

Weekly newsletter

With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.
  

 
DON'T
MISS

Fri, May 24th
    COPYRIGHT 1998-2013 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //