Widespread attacks exploit newly patched IE bug

By Robert McMillan, IDG News Service |  Security 3 comments

The first widespread attack to leverage a recently patched flaw in Microsoft's Internet Explorer browser has surfaced.

Starting late Wednesday, researchers at antivirus vendor Symantec's Security Response group began spotting dozens of Web sites that contain the Internet Explorer attack, which works reliably on the IE 6 browser, running on Windows XP. The attack installs a Trojan horse program that is able to bypass some security products and then give hackers access to the system, said Joshua Talbot, a security intelligence manager with Symantec.

Once it has infected a PC, the Trojan sends a notification e-mail to the attackers, using a U.S.-based, free e-mail service that Symantec declined to name.

As of midday Thursday, Symantec had spotted hundreds of Web sites that hosted the attack code, typically on free Web-hosting services or domains that the attackers had registered themselves.

The IE flaw being leveraged in these attacks was also used to hack into Google's corporate network last December. It has been linked to similar incidents at 33 other companies, including Adobe Systems. Microsoft patched the vulnerability in an emergency security update Thursday morning.

The Google attack hit IE 6 on Windows XP, but over the past week hackers have found ways to exploit the flaw on more recent versions of the browser as well. These latest techniques do not appear to be used on the Web sites Symantec has uncovered. They use the IE 6 exploit code, Talbot said.

Still, with IE 6 still being widely used, the move to more widespread attacks is worrying. "It may be an indication that attackers have finally ramped up their attack toolkits and are now ready to launch widespread attacks," Talbot said.

He believes that the criminals are tricking victims into visiting their Web sites by sending spam e-mail or instant messages with links to sites.

On Thursday, Websense published some sample e-mails used in targeted attacks that exploit the IE bug. A typical subject line is "Helping You Serve Your Customers." The e-mail reads, "I just heard the news: Helping you serve your customers" and includes a link to the malicious Web site.

The e-mails contain spoofed e-mail addresses, designed to fool victims into thinking that they were sent by a colleague. The malicious Trojan used in the attack is not the same one that was used in the Google attack, however.

Websense has seen these e-mails sent to targeted companies in the U.S. and the U.K., said Patrik Runald, a security research manager with Websense. "These attacks are actually continuing; they happened today; they happened yesterday and they happened the day before."

However, Websense believes that the e-mails it has tracked are part of a small-scale targeted attack, similar to those used on Google and Adobe in attacks that are ongoing. Websense has counted only about 25 malicious Web sites to date, but the number is rising fast, Runald said.

Security experts believe this more targeted technique is used as part of a systematic cyber-espionage campaign, which some have linked to China.

3 comments

    Anonymous 2 years ago
    But there are bad people in this World. No software is bullet proof. That does *not* mean that IE is as bullet proof as Firefox or all the other browsers. It's not. Bad people continue to sell a browser that has far more security holes than all the other browsers combined. Other bad people use those security holes to make malware to infect the security challenged browser. Lazy, uninformed people, continue to buy unsafe software when free and better software is available.Any article on a new virus/trojan should emphasize that the cybercriminals are not in control of computer security. The company who sells the affected software IS!Microsoft has been getting a free ride now for decades. They are the security problem. They made the computer security industry the huge success it is now. Huge success equals huge money, huge money siphoned off our economy.This is the kind of article that invites the "popularity" logic of the feeble minded. Let's see if he shows.
    Anonymous 2 years ago
    With all the attacks surfacing, all involving Internet Exploder, why are people STILL using IE? Logic would suggest switching to another browser until M$ can get their sh*t together and release a secure browser.
    Anonymous 2 years ago in reply to Anonymous
    Because some people are brainwashed into thinking they have to except computer insecurity. There are still those that go baaah to what ever Microsoft says.

      Add a comment

      Post a comment using one of these accounts
      Or join now
      At least 6 characters

      Note: Comment will appear soon after you have activated your account.
      Obscene/spam comments will be removed and accounts suspended.
      The information you submit is subject to our Privacy Policy and Terms of Service.

      ITworld LIVE

      SecurityWhite Papers & Webcasts

      White Paper

      A Proactive Approach to Server Security

      Learn why security-conscious organizations are taking a more proactive approach to server security. Download this Spire Research whitepaper to understand how you can eliminate the threat caused by today's more advanced threats and protect your organization's most valuable data.

      White Paper

      Protection Against Modern Cybersecurity Threats

      Download this case study to learn how this accounting and consulting giant uses Bit9's adaptive application whitelisting to offer employees flexibility without jeopardizing enterprise safety.

      White Paper

      Stop Hackers Before They Attack

      Hacktivism, Identify Theft, Financial Gain, Cyber War - regardless of motivation, stopping today's hackers requires a new proactive approach to protecting endpoints. Learn how this New England hospital, breached multiple times by targeted attacks, put an end to the malware with Bit9 Parity. Their IT team can now identify malware and secure PCs and workstations -protecting patient care and privacy.

      White Paper

      From the Frontline - Preventing APT

      Is your company's network secure? Are your endpoints and servers secured? Before you answer, read this case study on a US Military Command that discovered no matter how much you educate users, hackers can get through traditional defenses. This targeted attack blew through all layers of their security, except one: Bit9 Parity's advanced threat protection.

      White Paper

      Protecting Point of Sale Systems from Targeted Attack

      If you are responsible for protecting retail systems, download this case study to learn how this retailer eliminated the threat of malware on their POS systems using Bit9's award winning solutions.

      See more White Papers | Webcasts

      Ask a question

      Ask a Question