April 10, 2008

Free Tibet Web sites hacked

Malware on two pro-Tibet independence Web sites redirects visitors to a site that hosts a Trojan downloader

Malware has been detected on two pro-Tibet independence Web sites, in what could be a politically motivated attack, according to security supplier ScanSafe.

The security vendor detected the malware on FreeTibet.org and SaveTibet.org Web sites.

Visitors to the homepages of these sites are exposed to an iFrame that redirects visitors to a site that hosts a Trojan downloader. The Trojan then may download adware, spyware or other malware from multiple servers or sources on the internet, Scansafe said.

The malware infected site has been tracked to servers in Taiwan.

Spencer Parker, director of product management at ScanSafe said the attack on the human rights group sites appear to be politically motivated. "These Web sites appear to have been specifically targeted as this is not a generic Trojan downloader. Someone or some group has gone to great trouble to rewrite the exploit and personalize it to the FreeTibet.org and SaveTibet.org Web sites," he said.

"Given the recent events in Tibet and the protests around the forthcoming Olympics and the Olympic Torch Run, there may be certain groups that are particularly keen to monitor or disrupt activities of pro-Tibet interests."

ScanSafe recommended web surfers take extreme caution and that all Web sites review their security policies.

Computerworld UK is an InfoWorld affiliate.

 

Subscribe to the Security Central Newsletter

The one-stop resource center for IT professionals.

White Paper

CA Security Management Solutions

A comprehensive security management solution can help you streamline, as well as grow, your current or evolving business. In this way, a strategic security approach can help you increase your competitiveness in these challenging market conditions.

Download now! »

White paper

Beyond Compliance: The Significant Benefits of Log Management

Find out how you can effectively collect, normalize and archive enterprise-wide, security-related data that is invaluable for security investigation and compliance reporting.

Download now! »

Webcast

Integrated Identity Compliance: Enabling Cost-Effective Role-Based Compliance

This session focuses on the intersection of role management and identity compliance, and addresses the importance of identity compliance in enterprise governance and the challenges that organizations may face in achieving it.

View now! »
©1994-2009 Infoworld, Inc.