Blackhole Crimeware Goes Prime Time

  /     /     /  
Publicated : 22/11/2024   Category : security


Blackhole Crimeware Goes Prime Time


New HP OfficeJet phishing emails peaked at around 36,000 per minute on Wednesday



Attackers are increasingly using the Blackhole exploit kit in phishing campaigns: Most recently, one that poses as an email notification from an HP OfficeJet Printer has sent nearly 8 million emails thus far and uses 2,000 domains to serve up the malware.
Researchers at AppRiver say the trend demonstrates how Blackhole is following the pattern of popular crimeware kit Zeus and SpyEye. Blackhole traditionally has been used to infect legitimate websites for drive-by infection purposes. This attack is unique because Blackhole added an email vector to its format and is flooding the Internet with similar methods used by Zeus, SpyEye, and others, essentially moving it into prime time, says Fred Touchette, senior security analyst for AppRiver. The attackers also have set up their own malicious links to infect users who click on URLs in the emails.
Blackhole, which previously had been marketed as a high-end crimeware tool, costing $1,500 for a one-year license, in May was unleashed for free in some underground forums. That has propelled more use of the toolkit.
Touchette says he first noticed the trend with a Steve Jobs-themed email campaign earlier this month in the wake of Jobs death. This is the first that I have personally noticed that leads email recipients to Blackhole websites. Before that, people using the Blackhole Kit relied on techniques such as SEO poisoning to lead victims to their sites, he says.
The OfficeJet email campaign, like other Blackhole attacks, is trolling for victims online banking credentials. It works a lot like Zeus and others, using browser vulnerabilities on victims machines and creating a backdoor for downloading and installing the Trojans. AppRivers Touchette says Blackhole appears to favor Java and Adobe bugs.
This most recent campaign is still trickling in, but will soon stall as most of its domains have been picked up and blacklisted by security professionals. At its peak yesterday, we were seeing malicious emails related to this campaign coming in at a rate of around 36,000 per minute, he says. Links within those emails pointed toward approximately 2,000 separate domains that were hosting malicious code.
According to AVG Software, Blackhole infections peaked in March, with more than 8 million detections. They began dropping off in June, down to 4 million.
Recent botnet takedowns have spurred an increase in malware attacks recently as botnet operators try to rebuild, AppRivers Touchette says.
AppRiver posted a blog on the Blackhole attacks
here
yesterday.
Have a comment on this story? Please click Add Your Comment below. If youd like to contact
Dark Readings
editors directly,
send us a message
.

Last News

▸ 7 arrested, 3 more charged in StubHub cyber fraud ring. ◂
Discovered: 23/12/2024
Category: security

▸ Nigerian scammers now turning into mediocre malware pushers. ◂
Discovered: 23/12/2024
Category: security

▸ Beware EMV may not fully protect against skilled thieves. ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Blackhole Crimeware Goes Prime Time