This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. > Find out more here
by Shaun Nichols
01 Dec 2012
A report from security firm Sophos has concluded that the infamous Blackhole malware exploit kit originated in Russia.
Researcher Gabor Szappanos said in a teardown report on the Blackhole source code that a number of clues point towards Russia as the cradle of the wildly popular exploit kit which allows attackers to automatically target flaws for malware installations.
According to Szappanos, the developers of Blackhole left several key pieces of information available in the source code which suggest their location. Among the clues was the setting of Moscow as the default time zone location and the preference of Russian as the default interface language.
Other clues include the use of date formats unique to Eastern Europe and the presence of Cyrillic character encoding.
"All the evidence supports the assumption that the development of the Blackhole exploit kit occurred in Russia," Szappanos said.
The discovery of Blackhole's origin could prove useful for security researchers and law enforcement groups who are trying to stop the spread of Blackhole and apprehend the developers behind it.
The Blackhole kit has grown in recent years to become the most popular exploit kit on the internet. Researcher estimate that various builds of Blackhole are responsible for as much as one third of all drive-by malware attacks.
While the most recent versions of Blackhole can cost hundreds to thousands of dollars to purchase and maintain, older versions of the platform can be found for free on various cybercrime sites.
Recently, the platform showed signs of spreading as researchers uncovered 'Cool,' an attack toolkit which appears to be derived from Blackhole.
Latest stories from Security
Related videos
Related articles
Related jobs
Poll
How concerned are you by the rising tide of cyber threats?
A solid Android smartphone let down by less than stellar software
Updating your subscription status
Connect with V3.co.uk
It's no longer one or other with web security; you can now have a virtualisation and SaaS hybrid model
BYOD is important for employee satisfaction, but poses challenges in terms of security, productivity loss and costs
Delivery Project Manager - Energy, Risk Trading - London...
Delivery Consultant - Trading Commodities, ETRM, Energy...
Senior Web Designer -Adobe Photoshop / HTML / CSS / InDesign...
C# Winforms / Desktop Developer - C# / WPF / SQL Server...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree