The Broadband Guide
SG
search advanced

Hackers used previously unknown Internet Explorer flaw in new attacks

2014-02-14 09:14 by

 

FireEye Labs today discovered a new zero-day vulnerability in Internet Explorer 9 and Internet Explorer 10 being exploited on the US Veteran of Foreign Wars website (VFW). No user interaction is required: just visiting a compromised website is enough to trigger a classic drive-by download attack, download and install a payload from a remote server.

Dubbed "Operation Snowman," the campaign - believed to be operating out of China - is similar to Operation DeputyDog and Operation Ephemeral Hydra, both of which used zero-day flaws to deliver remote access trojans in order to hit strategically important targets.

"It's a brand new zero day that targets IE 10 users visiting the compromised website - a classic drive-by download attack," the firm said. "Upon successful exploitation, this zero-day attack will download [an] XOR encoded payload from a remote server, decode and execute it."

The hackers may have been aiming to compromise service members visiting the site, according to the manager of threat intelligence for FireEye. The VFW has 1.4 million members, including 75,000 still on active duty, according to its website.

Read more -here-

 

  Post your review/comments
    rate:
   avg:
News Glossary of Terms FAQs Polls Cool Links SpeedGuide Teams SG Premium Services SG Gear Store
Registry Tweaks Broadband Tools Downloads/Patches Broadband Hardware SG Ports Database Security Default Passwords User Stories
Broadband Routers Wireless Firewalls / VPNs Software Hardware User Reviews
Broadband Security Editorials General User Articles Quick Reference
Broadband Forums General Discussions
Advertising Awards Link to us Server Statistics Helping SG About