17 Oct 2009
The huge network of web pages compromised by the Gumblar botnet is now being used to spread malware, according to researchers.
Security firm ScanSafe reported that a number of pages connected to the Gumblar attacks in May had been serving malware to visitors.
The company noted that the attacks were unique in that, rather than infecting the pages to link to a single attack site, each of the compromised servers is hosting the malware on its own.
In addition to the compromised pages, the botnets operators have inserted a script that redirects users to a number of web forums.
"The majority of the compromised sites are small 'mom and pop' style sites in non-English speaking countries, but that's not important because the attackers have a clever trick for driving traffic directly to the malware hosted on those sites," said ScanSafe senior security researcher Mary Landesman in a blog posting.
First appearing in May, the Gumblar attack gained notoriety in the security world for the speed at which the malware spread. The attack not only compromised the target system, but checked for FTP credentials which were then used to target other pages.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Hands on with the highly anticipated Android 4.0 Ice Cream Sandwich hybrid tablet
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
/ Corporate Account Manager / Management Consultant...
Prince 2 Project Management Professional, Client Facing...
Solution Architect / Technical Project Manager / Corporate...
Solution Architect / Technical Project Manager / Corporate...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?