Tech Daily

News | Analysis | Comment | Features | Reviews

'Gumblar' botnet beginning to mobilise

Infected servers tied to malware attacks

Shaun Nichols in San Francisco, V3.co.uk 17 Oct 2009

The huge network of web pages compromised by the Gumblar botnet is now being used to spread malware, according to researchers.

Security firm ScanSafe reported that a number of pages connected to the Gumblar attacks in May had been serving malware to visitors.

The company noted that the attacks were unique in that, rather than infecting the pages to link to a single attack site, each of the compromised servers is hosting the malware on its own.

In addition to the compromised pages, the botnets operators have inserted a script that redirects users to a number of web forums.

"The majority of the compromised sites are small 'mom and pop' style sites in non-English speaking countries, but that's not important because the attackers have a clever trick for driving traffic directly to the malware hosted on those sites," said ScanSafe senior security researcher Mary Landesman in a blog posting.

First appearing in May, the Gumblar attack gained notoriety in the security world for the speed at which the malware spread. The attack not only compromised the target system, but checked for FTP credentials which were then used to target other pages.

See also:

Password screenWebsense warns of highly targeted assault  16 Oct 2009
Trojan horseMessageLabs warns malware is likely to go undetected  14 Oct 2009
Security padlockCompany hopes acquisition will bolster web-based security line  14 Oct 2009
SpamEmergence of new networks helps boost malware infections  30 Sep 2009

All Hacking
Tags: Gumblar, Scansafe, Botnet, Threats, Malware, Security

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

R E L A T E D   C O N T E N T