Security researcher Mahmoud Al-Qudsi spotted a âdrive-by-infectionâ hack on a compromised WordPress internet site in which the scam was working with JavaScript to change how text was displayed on the internet site, then urging end users to download a deal with for the issue. Al-Qudsi explained, âThis attack gets a whole lot of items appropriate that a lot of other individuals fail at. The premise is basically plausible: the text wonât render, and it claims that is brought about by a missing font, which it then prompts you to download and put in.â Screenshots present a warning box created by the hacker that seems authentic. A message exhibit claims: âThe web page you are seeking to load is displayed improperly as it uses the âHoefler Textâ font. To deal with the mistake and exhibit the text, you have to update the âChrome Font Packâ.â By clicking on the âUpdateâ button, which sports the suitable colour blue that Chrome uses, a file termed âChrome Font v7.five.one.exeâ downloads and the webpage morphs to âhelpfullyâ push the person to run the virus. This file is not recognised by possibly Windows Defender or Chrome as staying a virus. Only 9 out of 59 antivirus scanners identify it as hazardous. If infected, VirusTotal revealed the malware will snoop on files and files and can be utilized to inspect main Windows process files. Whilst Chrome wonât peg the file as staying destructive, it is blocked by a warning that claims âthis file isnât downloaded quite oftenâ. Tod Beardsley, investigation director at Rapid7 commented: âSo far, the assaults seem to be limited to compromised WordPress websites â a industry that is, regretably, wealthy with targets.â âChrome end users really should be knowledgeable that authentic warnings from the Chrome browser will never seem as overlays to a web page. Specifically, Chrome does not give any functionality for prompting for a missing font download, and all these types of prompts are sourced from malware or malvertising strategies. In the exceptional situations the browser desires to talk a safety or misconfiguration warning to the person, these warnings will seem as a comprehensive, substitution page, these types of as the familiar âYour relationship is not privateâ warning for misconfigured SSL certificates.â This article originally appeared at scmagazineuk.com
Source url Share this:Click to share on Twitter (Opens in new window)Click to share on Facebook (Opens in new window)Click to share on Google+ (Opens in new window)
Related
Security researcher Mahmoud Al-Qudsi spotted a âdrive-by-infectionâ hack on a compromised WordPress internet site in which the scam was working with JavaScript to change how text was displayed on the internet site, then urging end users to download a deal with for the issue.
Al-Qudsi explained, âThis attack gets a whole lot of items appropriate that a lot of other individuals fail at. The premise is basically plausible: the text wonât render, and it claims that is brought about by a missing font, which it then prompts you to download and put in.â
Screenshots present a warning box created by the hacker that seems authentic. A message exhibit claims: âThe web page you are seeking to load is displayed improperly as it uses the âHoefler Textâ font. To deal with the mistake and exhibit the text, you have to update the âChrome Font Packâ.â
By clicking on the âUpdateâ button, which sports the suitable colour blue that Chrome uses, a file termed âChrome Font v7.five.one.exeâ downloads and the webpage morphs to âhelpfullyâ push the person to run the virus.
This file is not recognised by possibly Windows Defender or Chrome as staying a virus. Only 9 out of 59 antivirus scanners identify it as hazardous. If infected, VirusTotal revealed the malware will snoop on files and files and can be utilized to inspect main Windows process files.
Whilst Chrome wonât peg the file as staying destructive, it is blocked by a warning that claims âthis file isnât downloaded quite oftenâ.
Tod Beardsley, investigation director at Rapid7 commented: âSo far, the assaults seem to be limited to compromised WordPress websites â a industry that is, regretably, wealthy with targets.â
âChrome end users really should be knowledgeable that authentic warnings from the Chrome browser will never seem as overlays to a web page. Specifically, Chrome does not give any functionality for prompting for a missing font download, and all these types of prompts are sourced from malware or malvertising strategies. In the exceptional situations the browser desires to talk a safety or misconfiguration warning to the person, these warnings will seem as a comprehensive, substitution page, these types of as the familiar âYour relationship is not privateâ warning for misconfigured SSL certificates.â
This article originally appeared at scmagazineuk.com