We have noticed a lot of SMS-based web-phishing attacks in China targeting the Bank of China’s online users. They received a phishing SMS that is designed to look like it was sent by the bank as a reminder to its customers: “Dear user, your token has expired, please visit http://www.boc**.com to reactivate your token.” The URL is similar to Read more…
Tags: Cybercrime, McAfee Labs, Network Security
Today, Microsoft released a security advisory on active attacks in the wild using a vulnerability in Microsoft Office Web Components. Computers installed with Microsoft Office features that uses vulnerable versions of the Microsoft Office Web Components could be infected with malware when browsing upon malicious websites in Internet Explorer. From our investigation, Exploit-CVE2009-1136, a new 0-day Read more…
In our blog from yesterday, we described how Exploit-MSDirectShow.b has been widely deployed on hijacked websites in China, targeting Internet Explorer users. When a victim browses one of these sites, malware is downloaded to the computer. To better understand the current impact of these attacks, we have monitored the prevalence of its downloaded malware through Artemis. Since Read more…
If you read Geok Meng and Xiaobo’s blog published in December last year, this must almost seem like a movie sequel. Over the July 4 weekend, an exploit targeting a zero-day vulnerability in the Microsoft Microsoft DirectShow ActiveX object was widely discovered on many Chinese websites. At the time of research, over a hundred hijacked sites were Read more…
Probably the most widely reported topic in the Chinese Security community this month will be the availability of a commercial MS08-067 attack pack, customized for Chinese users. On October 26th, 2008, exploit code was posted on to a well-known public repository site. In a few days, malware kit author, WolfTeeth, was quick to sell a Read more…
Earlier today, the Nanshan District Court of Shenzhen, in southern China, convicted 11 members of a password-theft syndicate to between six months and one year of imprisonment. According to the official press, the syndicate led by Jin has been operating from three malware development bases in northern China, each employing exploit developers, Web site hijackers, Read more…
Following our blog about the significance of web hosting security vs ARP spoofing, our friends from security vendor ESET made an official statement on October 9th, about an ARP attack against their official China website earlier this week. Identical to other ARP attacks, their web pages were found inserted with the following malicious IFRAME link: Read more…
In a follow up to our previous blog, the Chinese court system has convicted Li Jun to a 4 year prison sentence for authoring the W32/Fujacks virus on September 24, 2007. The W32/Fujacks virus (written in November 2006) spreads itself by infecting web pages, poorly secured file shares, and removable media amongst others. But the Read more…
Posts by Haowei Ren