JavaScript toolkit hit 10,000 websites in December: Finjan

More than 10,000 trusted websites were infected last month by the random js toolkit, elusive crimeware designed to send victims' personal information to attackers via the web, according to Finjan.

Yuval Ben-Itzhak, Finjan chief technology officer, said today that the toolkit uses three different methods of obfuscation to avoid detection and is simple to use.

“It's a very successful model. You no longer have to be a computer expert or have computer-science skills. You can pay $100 and have it put on a server you've already compromised,” he told SCMagazineUS.com today. “[The toolkits] have online reporting and they have automatic updates, so if Microsoft pushes a patch, they can make an adjustment.”

The toolkit targets users by embedding dynamic malicious script into the websites themselves. About 80 percent of pages hosting malicious software or drive-by downloads in 2007 were part of legitimate sites, according to Finjan.

The embedded malicious code does not appear on the trusted site after an end-user's first appearance, making the malware difficult to track, according to researchers at the San Jose, Calif.-based anti-virus vendor.

Two months ago, researchers at Exploit Prevention Labs, now a part of Grisoft, discovered malicious banner ads on the websites of Major League Baseball and the National Hockey League.

Finjan last week warned end-users that cybercriminals are on the verge of creating trojans designed specifically to take advantage of Web 2.0 technologies and social networking websites.

Ben-Itzhak said the toolkit is still serving malware to unexpecting end-users.

“It's still active. We first noticed it in mid-December and our servers indicated it's still alive and kicking,” he said. “It was serving as much as 14 million banners a week and almost all of them were malicious.”

More in News

Google hackers wanted to know which Chinese intel operatives were being watched

Attackers who raided Google in 2010 to learn information about Chinese human rights activists were also trying to gain insight on which Chinese intelligence agents were on the radar of U.S. authorities, according to a report.

California law would require breach notice if online account information is stolen

The new legislation would amend the definition of "personal information" under the state's breach notification law.

Liable to attack: Cyber insurance can help organizations cover the cost of breaches

Liable to attack: Cyber insurance can help organizations ...

Everyone is familiar with health, flood, car and life insurance, but what happens when the digital equivalent of a disaster strikes? Some entities may want this peace of mind, but ...