Slashdot Mirror


Malware Pulls an "Italian Job"

A number of readers sent us word about a malware attack that has been underway since Saturday that began with the compromise of more than 1,100 mostly Italian Web sites. Websense claims that more than 10,000 sites have been infected by now, 80% of them in Italy. There are indications that most of the Italian sites are resident at the same large Italian hosting provider. Trend Micro reports on the attack, which is launched from a malicious Iframe tag inserted into pages on compromised sites. For visitors to these sites, this begins a cascade of "drive-by" malware downloads if one of several targeted vulnerabilities is available and unpatched. The first page to which visitors are redirected by the Iframe hosts a recent version of Mpack attack software. Panda has a month-old report on Mpack (PDF) that provides copious detail about its nefarious ways.

2 of 133 comments (clear)

  1. Re:Super Mario Malware! by GFree · · Score: 0, Offtopic

    You know Italy is doing well for its cultural representation when "Super Mario" is the first thing that springs to mind.

  2. Re:Super Mario Malware! by beav007 · · Score: 0, Offtopic

    Really? For me it's hairy women. And yes, I'd prefer that it didn't spring to mind. It just does.

    Look! A distraction! *runs*