San Jose, CA, USA - 1st July 2009 – A second Indian government Web site - operated by the Institute of Remote Sensing - has been compromised for malware purposes, says Finjan Inc., a developer in secure web gateway products and the provider of unified web security solutions for the enterprise market.
News that the site has been hacked by cybercriminals comes after Finjan reported that the Government of India portal was hacked back in May of this year.
"This latest hack is interesting on two fronts. First the attack has happened despite the Indian government stepping up security on its hosting servers. And secondly, the cybercriminals have added a script into the site that adds an iFrame attack to the page," said Yuval Ben- Itzhak, Finjan's chief technology officer.
"The page then re-routes to a LuckySploit-infected server in Texas that fires off multiple attacks across the Internet. Early reports suggest that the site hack and re-route has infected several thousand Internet users," he added.
According to Ben-Itzhak, the LuckySploit toolkit uses a variety of methods to infect users and is notable for using a complex encryption system to hide what it is doing.
The bad news about this exploit is that the infected pages are only detected by 4 out of 41 anti-virus engines on the Virustotal.com code checking portal.
Finjan's malicious code research team has notified the Indian CERT operation about the problem, which we hope will be fixed shortly, said Ben-Itzhak.
"More than anything, this infection teaches us that any site can be compromised and serve malicious code without the site owner knowledge. This is why Web protection utilizing real-time content inspection is needed for businesses to prevent such attacks and keep their valuable data away from hackers," he said.
"Individual users should also consider installing a URL-checking browser plugin such as Finjan's free-to-use SecureBrowsing tool," he added.
About Finjan:
Finjan is a global provider of secure web gateway solutions for the enterprise market. Our real-time, appliance-based web security solutions delivers an effective shield against web-borne threats, freeing enterprises to harness the web for maximum commercial results. Finjan’s real-time web security solutions utilize patented behavior-based technology to repel all types of threats arriving via the web, such as spyware, phishing, Trojans, obfuscated code and other malicious code, securing businesses against unknown and emerging threats, as well as known malware.