Latin Best Buy surfers sprayed by drive-by download malware
¡Ay, Caramba!
Posted in Enterprise Security, 3rd July 2009 13:02 GMT
Free whitepaper – PowerEdge M1000e, M600 and M605 spec sheet
Hackers have invaded the Best Buy website to plant exploit code targeted at South and central American surfers.
The villanos have manipulated the page that allows surfers, visiting the site from Latin America, to select language preferences between either Spanish or English. Beneath layers of concealment, surfers are redirected towards a site that serves up exploit code - specifically the Luckysploit web exploit kit - via an iFrame.
"The Luckysploit web exploit kit and the obfuscation seen is reminiscent of that found in Gumblar," security researchers at Trend Micro explain.
Checks on the hacker controller website involved in the attack reveal that it was registered on 4 June by the same Ukranian gang that ran the earlier Gumblar attack back in March.
Trend Micro informed Best Buy of the attack, and is reportedly in the process of cleaning up its site.
A full write-up of the attack, complete with screenshots, can be found in a blog posting by Trend Micro here. ®

The Register Agile Data Center Summit
Analyst Keynote: The Register Agile Data Center Summit
Breaching Fort Apache.org - What went wrong?
Snow Leopard security - The good, the bad and the missing
US Dems fill inboxes with 419 scams
BlockMaster SafeStick hardware-encrypted USB drive