• Home
  • News
  • Reviews
  • Digital technology
  • Cloud
  • Data analytics
  • Digital leaders
  • IoT
  • Opinion
  • Events
  • Whitepapers
  • SMB Spotlight
  • Newsletters
  • Sign in
  • Events
    • Upcoming events
      event logo
      Big Data Virtual Summit

      The Big Data Virtual Summit will comprise expert keynotes, real world case studies and interactive discussion panels led by senior IT practitioners who will share their tips for Big Data technologies and data management strategies.

      • Date: 19 Oct 2016
      • Online
      View all events
      Follow V3 Events

      Sign up to receive email alerts about our events

      Sign up
  • Whitepapers
    • V3-resources-120x194
      Leveraging data for small businesses

      The most successful businesses are those with confidence in their ability to store, access and use data effectively.  Rather than focusing on the nuts and bolts of storage, this view point looks at the data it holds and more importantly, what can be done with it.

      Download
      V3-resources-120x194
      Getting the SMB network just right

      This review looks at why small businesses need to stop being complacent about their networks and at what they can do to maintain their competitive edge as they follow the big boys down the route of increasing collaboration and other bandwidth-hungry applications likely to impact on network performance and availability.

      Download
      Find whitepapers
      Search by title or subject area
      View all whitepapers
  • SMB Spotlight
  • Sign in
  •  
    •  

      Personalise your on site experience

      Download and use the apps

      Access your subscription from outside of the office

      Get relevant news and insight straight to your inbox

      Forgot your password?
     
     
      • Saved articles
      • Newsletters
      • Apps
      • Account details
      • Contact support
      • Sign out
     
  • Follow us
    • RSS
    • Twitter
    • Newsletters
    • Facebook
    • YouTube
    • Apps
  • Register
  • News
  • Reviews
  • Digital technology
  • Cloud
  • Data analytics
  • Digital leaders
  • IoT
  • Opinion
 
  •  

    Personalise your on site experience

    Download and use the apps

    Access your subscription from outside of the office

    Get relevant news and insight straight to your inbox

    Forgot your password?
 
 
    • Saved articles
    • Newsletters
    • Apps
    • Account details
    • Contact support
    • Sign out
 
V3.co.uk
  • Security

Criminals hosting child pornography on 227 business websites

Attackers could be planning ransomware cash grab against innocent web users

First Shellshock malware emerges
  • Alastair Stevenson
  • Alastair Stevenson
  • @MonkeyGuru
  • 06 August 2013
  • Tweet  
  • Facebook  
  •  
  •  
  • Save this article  
  • Send to  
0 Comments

Businesses' website are being illegally hijacked to forcibly store child pornography, according to the Internet Watch Foundation (IWF), in what security researchers believe could be a ransomware scam.

IWF technical researcher Sarah Smith uncovered the alarming trend after 227 small to medium-sized businesses, including a furniture store, reported falling victim to the attack.

She explained that the hack caused unsuspecting web users looking at legal adult content to be forcibly redirected to the business sites hosting the images.

"We hadn't seen significant numbers of hacked websites for around two years, and then suddenly in June we started seeing this happening more and more. It shows how someone, not looking for child sexual abuse images, can stumble across it," Smith said.

"The original adult content the internet user is viewing is far removed from anything related to young people or children."

The motivation for the attacks remains unknown, though Smith confirmed the IWF is tracking the movement of the attacks and is working to trace its origin.

"We've received reports from people distressed about what they've seen. Our reporters have been extremely diligent in explaining exactly what happened, enabling our analysts to retrace their steps and take action against the child sexual abuse images. Since identifying this trend we've been tracking it and feeding into police forces and our sister hotlines abroad," she said.

F-Secure security analyst Sean Sullivan told V3 the attack is likely the first stage in a wider campaign. "If this is in any way prevalent, I would suspect it is part of a ransomware or blackmail scheme," he said.

"From what I've read, malware is also pushed by the 'orphan' folder on the hacked site. And then – if a ‘police' ransomeware notification shows up a week later demanding that the victim pay a fine – I would very strongly doubt that the victim will seek tech support help, because they'll have seen an obscene image recently.

"The only other motivation that I can think of is some elaborate plot to publicise the need for a UK porn filter as 'porn' can lead to child abuse images. But I don't see why somebody would do that, as the government is already moving in that direction."

Independent security expert Graham Cluley mirrored Sullivan's sentiment confirming that the evidence suggests the attacks are not designed just to spread child pornography.

"I think it is unlikely that the offending images have been planted on the legitimate websites for the purposes of delivering the illegal content to paedophiles. It just doesn't seem plausible to me, and the chances for being discovered are too great," he wrote.

"Wouldn't it be an altogether more convincing and successful scam if the victims had been visiting adult websites, and found themselves unexpectedly looking at child abuse images? What better way to scare someone into paying a ransom than to tell them that they have been spotted accessing child pornography?

"Many people who receive a message like that would be petrified of contacting the police to check if it's true, or taking your PC down to the local computer store to be checked over."

Ramsomware is a dangerous form of malware that locks victims' computers and instructs them to pay a "fine" to have them unlocked. The malware has been a growing problem for firms, with new scams appearing on a near daily basis. Most recently ransomware posing as the US Department of Homeland Security and FBI were uncovered targeting unwary web users.

  • Tweet  
  • Facebook  
  •  
  •  
  • Save this article  
  • Send to  
  • Topics
  • Security
  • Web
  • malware
  • Hacking
  • cyber-crime

V3 Latest

Hacker with laptop
Oracle MICROS hack claims more victims

Five more firms caught up in huge attack

  • Security
  • 12 August 2016
oneplus-3-review-main
OnePlus 3 review

The OnePlus flagship goes invite-free for 2016

  • Mobile Phones
  • 12 August 2016
Text entry on WatchMI platform
Researchers show off pressure-touch and movement control tech for wearables

University of St Andrews researchers could have opened up a whole new world for wearables

  • Gadgets
  • 12 August 2016
volkswagen
Wireless hack flaw puts 100 million VW cars at risk

Car maker says 'there is no 100 per cent guarantee for security'

  • Security
  • 12 August 2016
blog comments powered by Disqus
Back to Top

Most read

oneplus-3-review-main
OnePlus 3 review
Microsoft Windows 10 on a laptop
Windows 10 Anniversary Update: 8 ways to tackle problems caused by latest release
Galaxy Note 7 render
Samsung Galaxy Note 7 release date, price, specs and features
Hacker with laptop
Oracle MICROS hack claims more victims
Microsoft Windows XP boxes on the assembly line in 2001
Windows XP: 7 reasons ancient OS refuses to die
  • Contact
  • Marketing solutions
  • Enterprise IT Events
  • About Incisive Media
  • Terms & conditions
  • Privacy policy
  • RSS
  • Twitter
  • Newsletters
  • Facebook
  • YouTube
  • Apps

© Incisive Business Media Limited

© Incisive Business Media (IP) Limited, Published by Incisive Business Media Limited, Haymarket House, 28-29 Haymarket, London SW1Y 4RX, are companies registered in England and Wales with company registration numbers 9177174 & 9178013

Digital publisher of the year 2010, 2013 & 2016

Digital publisher of the year 2010, 2013 & 2016