Feeds

Not Cool, man: Potent new hacking toolkit costs crooks $10k a month

Blackhole gang snap up latest 0-days to build a better mousetrap

Beginner's guide to SSL certificates

The brains behind the Blackhole Exploit Kit is using profits from the hacking toolbox to buy up security exploits and create a far more formidable product.

The ubiquitous Blackhole kit is usually installed on compromised websites and uses vulnerabilities in web browsers and other software to inject malware into visitors' PCs.

It is widely available through underground forums, and is affordable and reliable. Access to the technology is rented out for about $700 a quarter or $1,500 for a year, often bundled with web hosting fees of $500 a month, according to an investigation by Sophos.

Paunch, the main author of Blackhole, is now buying up code that exploits software security bugs from hackers and researchers to craft a far more powerful toolkit. Dubbed "Cool", this toolbox is available at a hefty $10,000 a month and is linked to a recent wave of successful online attacks.

The Cool Exploit Kit pack first surfaced in October and was used to push ransomware, which typically demands a victim to pay a fee to unlock his or her compromised computer. A French security researcher going by the name of Kafeine was among the first to notice the Cool kit using a critical vulnerability in Microsoft Windows (CVE-2011-3402). The flaw in the operating system's font processing code was first exploited by the cyber-espionage worm Duqu. That attack was added to the toolkit about a week later.

The same sequence of events happened with a Java runtime vulnerability (CVE-2012-5076) first abused by Cool mid-November, and later bundled in Blackhole. An analysis by F-Secure revealed similarities in the programming and functionality of the two exploit kits, which was further evidence that they were created by the same author or team.

Paunch admitted he created the Cool Exploit kit in an interview with investigative journalist Brian Krebs, and said his exploit framework costs $10,000 a month. "At first I thought Paunch might be pulling my leg, but that price tag was confirmed in a discussion by members of a very exclusive underground forum," Krebs noted.

An associate of Paunch posted a request for attack code on an underground cybercrime forum, and boasted that the group had a budget of $100,000 to buy exploits for unpatched web browser security bugs, as well as details of other undisclosed software flaws and tactics for improving the success rates of online assaults.

A portion of that message board post, translated from Russian by a professional translator, can be read on Krebs' website. The blogger concluded that the gang led by Paunch has moved on from exploiting vulnerabilities known to vendors, and likely patched by users, to relying on flaws that have not yet been disclosed to software makers - a dangerous development for web surfers and an expensive business for Paunch: getting hold of these so-called zero-day vulnerabilities is not cheap.

The Cool Exploit kit is been used by the Reveton ransomware gang. Symantec recently obtained access to a control panel and uncovered evidence [PDF] that the group was earning $30,000 A DAY through the scam, more than enough to justify the hefty outlay of an elite exploit pack. ®

Intelligent flash storage arrays

More from The Register

next story
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
You stupid BRICK! PCs running Avast AV can't handle Windows fixes
Fix issued, fingers pointed, forums in flames
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Designing and building an open ITOA architecture
Learn about a new IT data taxonomy defined by the four data sources of IT visibility: wire, machine, agent, and synthetic data sets.
How to determine if cloud backup is right for your servers
Two key factors, technical feasibility and TCO economics, that backup and IT operations managers should consider when assessing cloud backup.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.