By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
10alert.com10alert.com
  • Threats
    • WordPress ThreatsDanger
    Threats
    A cyber or cybersecurity threat is a malicious act that seeks to damage data, steal data, or disrupt digital life in general. Cyber threats include…
    Show More
    Top News
    Malware Reigned Supreme In 2012
    8 months ago
    First smartphone virus, Cabir, turns 10
    8 months ago
    Deep Dive: 5 Threats Affecting Hardware
    8 months ago
    Latest News
    Safeguards against firmware signed with stolen MSI keys
    1 day ago
    WPDeveloper Addresses Privilege Escalation Vulnerability in ReviewX WordPress Plugin
    1 day ago
    Wordfence Intelligence Weekly WordPress Vulnerability Report (May 15, 2023 to May 21, 2023)
    6 days ago
    Wordfence Firewall Blocks Bizarre Large-Scale XSS Campaign
    1 week ago
  • Fix
    Fix
    Troubleshooting guide you need when errors, bugs or technical glitches might ruin your digital experience.
    Show More
    Top News
    The creator of malware has infected her own computer
    8 months ago
    Windows 11 build 25163 out with new Taskbar Overflow feature
    8 months ago
    How to fix Microsoft Store not working on Windows 11
    8 months ago
    Latest News
    How automatically delete unused files from my Downloads folder?
    4 months ago
    Now you can speed up any video in your browser
    4 months ago
    How to restore access to a file after EFS or view it on another computer?
    4 months ago
    18 Proven Tips to Speed Up Your WordPress Site and Improve SEO | 2023 Guide
    5 months ago
  • How To
    How ToShow More
    What is two-factor authentication | Kaspersky official blog
    2 days ago
    Acer refreshes Windows 11 PCs for work and play: Swift Edge 16 and Predator Triton 16
    4 days ago
    NVIDIA GeForce RTX 4080 New Mercury Editions of Razer Blade 16 and Blade 18 now available
    4 days ago
    How Oxy uses hooks for maximum extensibility
    How Oxy uses hooks for maximum extensibility
    5 days ago
    The personal threat landscape: securing yourself smartly
    5 days ago
  • News
    News
    This category of resources includes the latest technology news and updates, covering a wide range of topics and innovations in the tech industry. From new…
    Show More
    Top News
    How to delete Automatically cookie files
    8 months ago
    Millions servers affected by Exim software
    8 months ago
    AutoComplete WooCommerce Virtual Products
    8 months ago
    Latest News
    How to create virtual drive (VHD, VHDX, Dev Drive) on Windows 11
    2 days ago
    How to enable Taskbar End Task option to close apps on Windows 11
    2 days ago
    How to check USB4 devices specs from Settings on Windows 11
    2 days ago
    How to enable new header UI for File Explorer on Windows 11
    1 week ago
  • Glossary
  • My Bookmarks
Reading: Web Malware: Out of the Shadows and Hiding in Plain Sight
Share
Notification Show More
Aa
Aa
10alert.com10alert.com
  • Threats
  • Fix
  • How To
  • News
  • Glossary
  • My Bookmarks
  • Threats
    • WordPress ThreatsDanger
  • Fix
  • How To
  • News
  • Glossary
  • My Bookmarks
Follow US
ThreatsWordpress Threats

Web Malware: Out of the Shadows and Hiding in Plain Sight

Vitus White
Last updated: 13 October
Vitus White 8 months ago
Share
5 Min Read

There is an all-too common misconception that in order to become infected with web-propagated malware, you must visit sketchy parts of the Internet’s underbelly or a website within that broad class of which is “not safe for work.” Thus, when you admit to your buddies that your computer is beset by malware, one of them invariably makes some sort of joke about how you’ve been spending too much time on this or that pornographic website.

In reality though, the old days of becoming infected with malware by visiting adult websites are largely over. Those websites, unlike most, probably make money. Therefore, it behooves them to ensure that they are not infected with malware.

In my experience, most malware infected websites are the ones that no one expects to be infected with malware.

With any malware infection, there are really two primary philosophies, trawling and spear-phishing. On the one hand, you can cast as wide a net as possible in order to catch as many fish as possible; the strategy for botnet operators and the progenitors of banking trojans. On the other hand, you pick a fish, go to where it lives, set your hook with the kind of bait you know it likes to eat, and catch it. Likewise, you can find a vulnerability in a popular site and infect it with malware in order to draw in as many infections as possible. Or you can find a vulnerability in a site that you think your intended target will visit. This second method has a name. Its name is a watering hole attack, which derives from wilderness reality that ambush predators hide near water sources, where they know their prey will eventually have go to drink. These predators merely wait until their prey’s head is down to drink, and they attack. Similarly, an attacker will estimate which sites his target is likely to visit and look for vulnerabilities in them.

The broad-style of attack manifested itself last week when the popular humor website cracked[dot]com was infected with malware. Researchers from Barracuda Labs expressed concerns that the number of infections arising from this attack could be quite high considering that the site ranks 289 in the U.S. and 654 globally, according to the Web information firm, Alexa. Similarly, the web-developer resource site PHP[dot]net was recently infected according to Spiderlabs research, as were a small handful of Russian banking sites (you may need to brush up on your Russian to read this).

The more refined or targeted style of attack is perhaps best demonstrated by the rash of watering hole attacks targeting the Department of Labor websites earlier this year. In this case, the targets were likely individuals with access to sensitive government networks. More recently, researchers from the security firm FireEye reported a watering hole attack against an unnamed U.S.-based non-governmental organization (NGO) website hosting domestic and international policy guidance.

In general, the point is this: who would think that the Department of Labor’s website would be serving malware? But that’s the point exactly: to infect an unlikely site where visitors have their guards down.

There is no such thing as perfect security. You never know where an attacker may be hiding malware. They use automated tools to determine which websites contain exploitable vulnerabilities. Therefore, you’re dually relying on the website administrators install updates that will have to have been built by the various software vendors. If admins are anything like normal Internet user’s then they probably aren’t very good about implementing patches. For sure, vendors are much better than they used to be about building patches, but there are still an alarming number of companies in this space with no patch schedule whatsoever.

Because of all of this, the easiest way to protect yourself from websites containing malware is to run an antivirus program, pay attention to browser warnings, and read security news, whether you are surfing on your PC, Mac, tablet or phone.


Source: kaspersky.com

Translate this article

TAGGED: DoS, Malware, Phishing, PoC, Security, Software, Threats, Vulnerabilities
Vitus White October 13, 2022 October 7, 2022
Share this Article
Facebook Twitter Reddit Telegram Email Copy Link Print

STAY CONECTED

24.8k Followers Like
253.9k Followers Follow
33.7k Subscribers Subscribe
124.8k Members Follow

LAST 10 ALERT

Safeguards against firmware signed with stolen MSI keys
Threats 1 day ago
WPDeveloper Addresses Privilege Escalation Vulnerability in ReviewX WordPress Plugin
WPDeveloper Addresses Privilege Escalation Vulnerability in ReviewX WordPress Plugin
Wordpress Threats 1 day ago
How to create virtual drive (VHD, VHDX, Dev Drive) on Windows 11
News 2 days ago
How to enable Taskbar End Task option to close apps on Windows 11
News 2 days ago
How to check USB4 devices specs from Settings on Windows 11
News 2 days ago

Recent Posts

  • Safeguards against firmware signed with stolen MSI keys
  • WPDeveloper Addresses Privilege Escalation Vulnerability in ReviewX WordPress Plugin
  • How to create virtual drive (VHD, VHDX, Dev Drive) on Windows 11
  • How to enable Taskbar End Task option to close apps on Windows 11
  • How to check USB4 devices specs from Settings on Windows 11

You Might Also Like

Threats

Safeguards against firmware signed with stolen MSI keys

1 day ago
WPDeveloper Addresses Privilege Escalation Vulnerability in ReviewX WordPress Plugin
Wordpress Threats

WPDeveloper Addresses Privilege Escalation Vulnerability in ReviewX WordPress Plugin

1 day ago
News

How to create virtual drive (VHD, VHDX, Dev Drive) on Windows 11

2 days ago
How To

What is two-factor authentication | Kaspersky official blog

2 days ago
Show More

Related stories

How to Use Cloudflare to Secure Your WordPress Site
How To Starting Chrome from the command line
How to fix error 0x80070057 in Chrome?
Windows 10 How To Disable Slide to Shutdown
Windows search not working (FIX)
How to watch movies and TV series for free on Kinopoisk?
Previous Next

10 New Stories

What is two-factor authentication | Kaspersky official blog
Acer refreshes Windows 11 PCs for work and play: Swift Edge 16 and Predator Triton 16
NVIDIA GeForce RTX 4080 New Mercury Editions of Razer Blade 16 and Blade 18 now available
How Oxy uses hooks for maximum extensibility
The personal threat landscape: securing yourself smartly
Wordfence Intelligence Weekly WordPress Vulnerability Report (May 15, 2023 to May 21, 2023)
Previous Next
Hot News
Safeguards against firmware signed with stolen MSI keys
WPDeveloper Addresses Privilege Escalation Vulnerability in ReviewX WordPress Plugin
How to create virtual drive (VHD, VHDX, Dev Drive) on Windows 11
How to enable Taskbar End Task option to close apps on Windows 11
How to check USB4 devices specs from Settings on Windows 11
10alert.com10alert.com
Follow US

© 10 Alert Network. All Rights Reserved.

  • Privacy Policy
  • Contact
  • Customize Interests
  • My Bookmarks
  • Glossary
Go to mobile version
adbanner
AdBlock Detected
Our site is an advertising supported site. Please whitelist to support our site.
Okay, I'll Whitelist
Welcome Back!

Sign in to your account

Lost your password?