Feeds

Not Cool, man: Potent new hacking toolkit costs crooks $10k a month

Blackhole gang snap up latest 0-days to build a better mousetrap

Reducing security risks from open source software

The brains behind the Blackhole Exploit Kit is using profits from the hacking toolbox to buy up security exploits and create a far more formidable product.

The ubiquitous Blackhole kit is usually installed on compromised websites and uses vulnerabilities in web browsers and other software to inject malware into visitors' PCs.

It is widely available through underground forums, and is affordable and reliable. Access to the technology is rented out for about $700 a quarter or $1,500 for a year, often bundled with web hosting fees of $500 a month, according to an investigation by Sophos.

Paunch, the main author of Blackhole, is now buying up code that exploits software security bugs from hackers and researchers to craft a far more powerful toolkit. Dubbed "Cool", this toolbox is available at a hefty $10,000 a month and is linked to a recent wave of successful online attacks.

The Cool Exploit Kit pack first surfaced in October and was used to push ransomware, which typically demands a victim to pay a fee to unlock his or her compromised computer. A French security researcher going by the name of Kafeine was among the first to notice the Cool kit using a critical vulnerability in Microsoft Windows (CVE-2011-3402). The flaw in the operating system's font processing code was first exploited by the cyber-espionage worm Duqu. That attack was added to the toolkit about a week later.

The same sequence of events happened with a Java runtime vulnerability (CVE-2012-5076) first abused by Cool mid-November, and later bundled in Blackhole. An analysis by F-Secure revealed similarities in the programming and functionality of the two exploit kits, which was further evidence that they were created by the same author or team.

Paunch admitted he created the Cool Exploit kit in an interview with investigative journalist Brian Krebs, and said his exploit framework costs $10,000 a month. "At first I thought Paunch might be pulling my leg, but that price tag was confirmed in a discussion by members of a very exclusive underground forum," Krebs noted.

An associate of Paunch posted a request for attack code on an underground cybercrime forum, and boasted that the group had a budget of $100,000 to buy exploits for unpatched web browser security bugs, as well as details of other undisclosed software flaws and tactics for improving the success rates of online assaults.

A portion of that message board post, translated from Russian by a professional translator, can be read on Krebs' website. The blogger concluded that the gang led by Paunch has moved on from exploiting vulnerabilities known to vendors, and likely patched by users, to relying on flaws that have not yet been disclosed to software makers - a dangerous development for web surfers and an expensive business for Paunch: getting hold of these so-called zero-day vulnerabilities is not cheap.

The Cool Exploit kit is been used by the Reveton ransomware gang. Symantec recently obtained access to a control panel and uncovered evidence [PDF] that the group was earning $30,000 A DAY through the scam, more than enough to justify the hefty outlay of an elite exploit pack. ®

Mobile application security vulnerability report

More from The Register

next story
LibreSSL RNG bug fix: What's all the forking fuss about, ask devs
Blow to bit-spitter 'tis but a flesh wound, claim team
Microsoft: You NEED bad passwords and should re-use them a lot
Dirty QWERTY a perfect P@ssword1 for garbage websites
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
NUDE SNAPS AGENCY: NSA bods love 'showing off your saucy selfies'
Swapping other people's sexts is a fringe benefit, says Snowden
Own a Cisco modem or wireless gateway? It might be owned by someone else, too
Remote code exec in HTTP server hands kit to bad guys
British data cops: We need greater powers and more money
You want data butt kicking, we need bigger boots - ICO
Crooks fling banking Trojan at Japanese smut site fans
Wait - they're doing online banking with an unpatched Windows PC?
NIST told to grow a pair and kick NSA to the curb
Lrn2crypto, oversight panel tells US govt's algorithm bods
prev story

Whitepapers

Top three mobile application threats
Prevent sensitive data leakage over insecure channels or stolen mobile devices.
The Essential Guide to IT Transformation
ServiceNow discusses three IT transformations that can help CIO's automate IT services to transform IT and the enterprise.
Mobile application security vulnerability report
The alarming realities regarding the sheer number of applications vulnerable to attack, and the most common and easily addressable vulnerability errors.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.