Ad-based Trojan hits MySpace, Bebo and others

Malware hidden in adverts

Matt Chapman

Users of high profile sites including MySpace, The Sun, Bebo and PhotoBucket have been exposed to a Trojan hidden within adverts.

The sites all ran advertising in recent weeks from the Right Media online ad exchange which were unknowingly infected with the Downloader.VBS.Agent.n Trojan.

Advertisement

"This is another example of how legitimate 'trusted' websites can unknowingly host malware," said Dan Nadir, vice president of product strategy at ScanSafe.

"Online ads have become a primary target for malware authors because they offer a stealthy way to distribute malware to a wide audience."

Nadir explained that the malware was particularly dangerous because it required no user interaction for infection to take place.

ScanSafe estimates that up to 12 million ads may have been delivered, exposing a large number of users to the Trojan.

The security vendor saw a surge in blocks of the Trojan beginning on 8 August and continuing until early September.

Nadir added that it will be very difficult to track down the source of the malware because the hacker used the distributed nature of online advertising to spread the code to hundreds of sites.

One of the infected adverts used a Flash file to generate an invisible iFrame. This was linked to an IP address containing obfuscated visual basic script that used the well-known MDAC exploit to download a Trojan executable.

ScanSafe believes that the malicious script inside the Flash ad avoided detection by Right Media because of the clever use of a referrer check. This meant that the advert only became active when delivered by a particular ad server.

The Downloader.VBS.Agent.n malware downloads other programs which are launched on the victim's machine without knowledge or consent.

ScanSafe said that several well known sites, including TomsHardware, have unwittingly hosted malware that was inserted via infected online ads.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Storm worm back with a vengeance

Quarter of all detected threats during August, says BitDefender

Malware-laden spam promises pop videos

Email links lead to malicious script and Trojan horse

Web hosting firm harbours virus

Not known how far infection has spread

Cyber-criminals unleash spam Storm

Experts warn of 'confirmation spam' outbreak

Related whitepapers

Related jobs

Most watched

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

Xperia X1

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1

IT white papers

Search white papers

Top categories

Poll

Poll: Summer smartphones

Poll: Summer smartphones

Which smartphone will you be taking to the beach this summer?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

old computer

Government honours veterans of Bletchley Park at last

Surviving veterans of the code-breaking facility to receive badge of...

Motorola MC55 Enterprise Digital Assistant

Review: Motorola MC55 Enterprise Digital Assistant

A rugged Windows Mobile device for mobile workers

BT

BT promises 1.5m fibre connections by summer 2010

Telco begins major rollout in 69 locations across the UK

Primary Navigation