News & Information for Technology Purchasers
NewsFactor Network Sites:   NewsFactor.com Security CRM Business Sci-Tech Newsletters XML/RSS Feed  
   
Home Enterprise I.T. Hardware Software Communications More Topics...
Network Security
Average Rating:
Rate this article:  
Security Experts Monitor MPack Threat Security Experts Monitor MPack Threat
By Jennifer LeClaire
June 21, 2007 9:57AM

    Bookmark and Share
Also known as WebAttacker II, MPack dates back to October 2006 and accounted at that time for roughly 10 percent of Web-based attacks. "MPack is a powerful Web exploitation tool that claims about 50 percent success in attacks silently launched against Web browsers," said Ken Dunham, director of the rapid response team at VeriSign iDefense.
 



While the U.S. Department of Homeland Security continues to try to secure its virtual borders, security researchers are digging more deeply into a computer infection that started in Italy and might soon spread beyond European shores.

Trend Micro initially reported the infection of seemingly legitimate Web pages loaded with malicious code that can install keyloggers to steal user passwords or turn computers into proxy servers for various other attacks.

The malware takes advantage of iFrames, which are commonly used on Web sites to nest content within pages. Trend Micro researchers believe the malware was generated with a Trojan-creation toolkit called MPack.

Trend Micro data Relevant Products/Services indicates that tens of thousands of users worldwide have accessed malicious URLs, oblivious to the MPack threat. VeriSign's iDefense, for its part, is reporting that the MPack attacks are gaining momentum.

50/50 Success

"MPack is a powerful Web exploitation tool that claims about 50 percent success in attacks silently launched against Web browsers," said Ken Dunham, senior engineer and director of the rapid response team at VeriSign's iDefense. "'$ash' is the primary Russian actor attempting to sell MPack on the underground for about $1,000 for the complete MPack kit."

Also known as WebAttacker II, MPack dates back to October 2006 and accounted at that time for roughly 10 percent of Web-based attacks. According to iDefense, more than 10,000 domains in the recent rise of MPack attacks compromised some 80,000 unique IP addresses in Italy.

Verisign's iDefense maintains that it is likely that exploitation took place through the cPanel software that many Web hosting providers offer their customers as a way to manage their Web sites. This cPanel infection led to malicious iFrames being injected on the sites in question.

"MPack leverages multiple exploits, in a very controlled manner, to compromise vulnerable computers," Dunham explained. "Exploits range from the recent animated cursor [vulnerability] to QuickTime exploitation." The latest version of the MPack toolkit even includes code to exploit specific Microsoft Relevant Products/Services vulnerabilities covered in several of the company's security bulletins.

The Payload

The well-known Torpig Trojan is one of the known payloads for MPack, VeriSign reported. The Torpig Trojan is tied closely to the Russian Business Network (RBN), through which many Internet-based attacks take place today.

The RBN has become a virtual safe house for attacks out of Saint Petersburg, Russia, responsible for phishing, child pornography, and other illicit operations, Dunham noted.

"MPack attacks experience high success, according to attack log files analyzed by VeriSign iDefense," Dunham concluded. "In just a few hours, more than 2,000 new victims reported to an MPack command and control Web site."
 

Tell Us What You Think
Your Comment:



Advertisement


 Network Security
1.   China Cyberattacks: Pervasive Threat
2.   Patch Tuesday Will Tie MS Record
3.   Cybersecurity Appears Hot for 2010
4.   EPIC Objects To Google-NSA Ties
5.   Torrent Traps Used To Harvest Logins


advertisement
EPIC Objects To Google-NSA TiesEPIC Objects To Google-NSA Ties
Cyberattack meant to rattle Google?
Average Rating:
Torrent Traps Used To Harvest LoginsTorrent Traps Used To Harvest Logins
Web sites sold with backdoor access.
Average Rating:
Social Networks: A Hacker's DelightSocial Networks: A Hacker's Delight
Workers urged to be 'trained skeptics.'
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Enterprise Hardware Spotlight
Nvidia Auto-Switches Notebook GPU To Save Battery Life
Nvidia has taken the wraps off a notebook technology that chooses the best graphics processor for any given application and automatically routes the workload to Nvidia or Intel processors.
 
Microsoft Says Battery Woes Not Caused By Windows 7
Battery problems on Windows 7 machines are not caused by the operating system. That's the position of Stephen Sinofsky, head of the Windows division, in a long posting on the Windows engineering blog.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 

Enterprise Technology Spotlight
Intel Launches Quad-Core Itanium 9300 Series Processor
After two unexpected delays, Intel has launched the Itanium 9300 series, a 64-bit, quad-core processor code-named Tukwila that is expected to double the performance of its predecessor.
 
Google May Add Facebook, Twitter Links to Gmail
Google will reportedly roll more social-networking features into Gmail, the fastest-growing e-mail service. The new features could save users the trouble of switching to Facebook or Twitter.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Hardware | Software | Communications | Network Security | Wireless Tech | Linux/Open Source
Apple/Macintosh | Microsoft/Windows | World Wide Web | Data Storage | E-Commerce | Personal Tech | Tech Trends | Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo.