China seen targeting banks, military in Forbes web attack

A Chinese hacking group infiltrated the Forbes.com site in November and used it to launch targeted attacks against website visitors from U.S. banking and defense companies, a cybersecurity company said on Tuesday.

The attack took place over a period of several days, starting Nov. 28, and took advantage of unpatched vulnerabilities in Adobe Flash and Microsoft Internet Explorer 9, according to ISight Partners. The vulnerability was kept quiet until Tuesday, when Microsoft issued a patch to plug the security hole in its web browser. Adobe had previously published a patch for Flash.

ISight said the attack has the fingerprints of a Chinese hacking group known by security researchers as either Codoso or Sunshop Group. It said technical indicators in the malware as well as use of the same undisclosed vulnerabilities as used in other hacks by Chinese groups led to this conclusion.

Among ISight’s evidence: some of the malware code was written in simplified Chinese, used in mainland China, and it bore a resemblance to the “Derusbi” malware that is unique to Chinese hackers. The command system for the malware relied on an Internet domain previously used in Chinese hacks and pointed to web pages that had been used in Chinese attacks in the past.

Full article: China seen targeting banks, military in Forbes web attack (Computer World)

Comments are closed.