Attacks/Breaches
2/22/2013
09:25 AM
50%
50%

NBC Websites Hacked To Serve Citadel Financial Malware

RedKit exploit kit launched drive-by malware attacks from NBC websites, targeted vulnerabilities in Java and Adobe Reader.

Multiple NBC websites were compromised by online attackers and used to launch drive-by attacks at visitors Thursday.

"At 16:43 CET [12:43 EST] this afternoon we noticed that the NBC.com website links to the redkit exploit kit that is spreading Citadel malware, targeting U.S. financials (sic) institutions," warned security analyst Barry Weymes at Dutch security firm Fox-IT in a Thursday blog post. "This version of Citadel is only recognizable by 3 out of the 46 antivirus programs on virustotal.com."

Malware-spewing NBC websites included the sites for Late Night with Jimmy Fallon and Jay Leno's Garage, according to a blog posted by Tony Perez, COO of security software vendor Sucuri.

In short order, Google was blocking some NBC websites from search results, warning that they appeared to be infected with malware. While some reports suggested that NBC expunged the malware after just 15 minutes, multiple security researchers reported that the infections persisted for at least four hours.

[ Attend Interop Las Vegas, May 6-10, and get the most thorough training on Apple Deployment at the NEW Mac & iOS IT Conference. Use Priority Code DIPR02 by March 2 to save up to $500. ]

Attackers appeared to have compromised the NBC websites using the RedKit attack toolkit, which then targeted users with attacks designed to exploit vulnerabilities in their Java browser plug-in, or Adobe Reader. The remotely exploitable Java bug (CVE-2013-0422) being targeted was discovered in January and patched last month. Meanwhile, the malicious PDF file served up by the malware was recognized Friday morning by only six out of 46 antivirus software packages, according to VirusTotal. Initial reports on the attack from security researchers didn't disclose if the Adobe Reader bug was a zero-day flaw, or previously discovered bug.

The iframe used in the attack called on an ever-changing list of external URLs to load attack code. "This tells us that something on the server is generating the payload," said Sucuri's Perez in his Thursday blog post. "This isn't an uncommon practice, it also tells us that the script is likely still on the box. The fact that it's impacting other sites tells us that the compromise might extend beyond the Web application and onto the server. If those other sites are stored on separate boxes then we're looking at a much bigger, network, compromise, but that is speculative at the moment."

By infecting a high-profile site such as NBC.com, which is one of the top 600 most popular sites in the United States, attackers had the opportunity to quickly infect numerous visitors. "Targeting media and news websites can vastly improve an attacker's chances of success," according to Fox-IT's Weymes, which was one of the first organizations to spot the attack. "Users presume these large organizations' websites to be free from malware. If an attacker can gain access to these Web servers, they can use them to distribute malware to every visitor of that Web server."

Attackers made the most of their exploit window, using RedKit to target PCs with up to three different exploit kits, including the Citadel crimeware toolkit, which is designed to steal financial information. According to Fox-IT, the attackers were targeting account details for numerous U.S. financial institutions, including American Express, Bank of America, Chase, Citibank, Citizensbank Online, Fifth Third Bank, Navy Federal Credit Union, PNC, Schwab, Suntrust, TD Ameritrade, USAA and Wells Fargo.

The drive-by NBC website attacks also infected some visitors with ZeroAccess malware, which is used to launch clickjacking attacks that generate fake pay-per-click revenues for botnet controllers or their clients. "ZeroAccess is a dangerous threat that uses stealth techniques in order to hinder its detection and removal," said SurfRight security researcher Erik Loman in a blog post.

RedKit served up a third piece of malware which has yet to be identified. "Some antivirus vendors identify this malware as Zbot or a rootkit ... but it is most definitely not Zbot and it's not a rootkit either," Loman said. "The malware binary has a curious name at the end 'SadokBdi,'" which may connect it to previously seen malware known as "Sadok."

The timing of the high-profile NBC attack may be tied to Oracle and Adobe having recently released patches for multiple critical vulnerabilities in Java, Reader and Acrobat. Once vendors release a patch, criminals often reverse-engineer the fix to reveal the underlying vulnerability, which they then begin targeting. Anyone who doesn't quickly update their software thus remains highly vulnerable to having their PC compromised by an attacker, which can lead to their personal financial account information being stolen, keystrokes recorded and their PC being made to serve as part of a botnet.

Owing to many users failing to update the Java Runtime Environment installed on their PCs, Java bugs in particular remain quite popular with -- and effective for -- attackers.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
OtherJimDonahue
50%
50%
OtherJimDonahue,
User Rank: Apprentice
2/22/2013 | 8:52:22 PM
re: NBC Websites Hacked To Serve Citadel Financial Malware
Put the malware on NBC's prime time schedule and it will be canceled within two episodes.

Jim Donahue
Copy Chief
InformationWeek
Deirdre Blake
50%
50%
Deirdre Blake,
User Rank: Apprentice
2/22/2013 | 3:35:18 PM
re: NBC Websites Hacked To Serve Citadel Financial Malware
Bummer, I there'll be no slow jamming the news today.
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-1750
Published: 2015-07-01
Open redirect vulnerability in nokia-mapsplaces.php in the Nokia Maps & Places plugin 1.6.6 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the href parameter to page/place.html. NOTE: this was originally reported as cross-sit...

CVE-2014-1836
Published: 2015-07-01
Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows remote attackers to delete arbitrary files via a full pathname in the image_path parameter in a cancel action.

CVE-2015-0848
Published: 2015-07-01
Heap-based buffer overflow in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP image.

CVE-2015-1330
Published: 2015-07-01
unattended-upgrades before 0.86.1 does not properly authenticate packages when the (1) force-confold or (2) force-confnew dpkg options are enabled in the DPkg::Options::* apt configuration, which allows remote man-in-the-middle attackers to upload and execute arbitrary packages via unspecified vecto...

CVE-2015-1950
Published: 2015-07-01
IBM PowerVC Standard Edition 1.2.2.1 through 1.2.2.2 does not require authentication for access to the Python interpreter with nova credentials, which allows KVM guest OS users to discover certain PowerVC credentials and bypass intended access restrictions via unspecified Python code.

Dark Reading Radio
Archived Dark Reading Radio
Marc Spitler, co-author of the Verizon DBIR will share some of the lesser-known but most intriguing tidbits from the massive report