Hacked NBC websites infected unsuspecting visitors with malware


Newsletter not displayed correctly? Online Version - Unsubscribe? Please see bottom
Emsisoft Homepage

Salzburg, February 27th, 2013

Hacked NBC websites infected unsuspecting visitors with malware

A few days ago, unknown hackers managed to gain access to the web servers of the major American network, NBC. Several websites owned by the network were used to infect unprotected PCs with malicious software. All you had to do was access the website through your browser on an unpatched PC. Once again, Emsisoft Anti-Malware users can consider themselves fortunate though, as their computers had the ultimate protection!
There are many people who still believe they can remain safe on the internet simply by surfing carefully. Unfortunately, this belief became the ultimate downfall for countless visitors of NBC's website. Tens of thousands of users risked infecting their PCs with malware by simply accessing NBC.com and several sub-domains like those of talk show hosts Jimmy Fallon and Jay Leno.
Our Emsisoft security experts discovered and analyzed the attack within mere minutes of its onset. If you think this incident isn't of concern to you because you have never visited NBC.com, remember that it could happen again - to any site, at any time.

What happened exactly?

As yet unknown hackers gained access to NBC's web servers on February 21st. They injected malicious iFrames into the source code of several websites. The injected code ran the RedKit Exploit Kit which scans a visitor's PC for vulnerabilities in installed software.
These vulnerabilities or exploits grant the hacker access to your system so they can then install malware. Once again, vulnerabilities in Adobe Reader and Java Runtime Environment were targeted. The malware used in this attack was Citadel and ZeroAccess - two well-known bots that allow a hacker full control of infected PCs.

How can I protect myself?

This incident has highlighted the efficiency of Emsisoft Anti-Malware's behavior blocker once again. Whereas pure signature-based anti-virus solutions were almost powerless against this attack using brand-new malware, Emsisoft users were fully protected from the very beginning without waiting for signature updates. The bots used in this attack were detected by their behavior and neutralized effectively.
Test it free of charge for 30 days, without tedious registration!
Even trustworthy web portals can quickly turn into huge malware-spreading machines during a malware hack attack. There was no indication to visitors at any time during the attack that this website was a potential risk. For further technical analysis of this incident, please see our Emsisoft Blog.
Important information on how to secure your PC can also be found in Emsisoft's knowledgebase: 10 steps to make your PC safe for 2013.
Have a nice (malware-free) day!

Christian Mairoll - Emsisoft CEO
FacebookTwitterMore...Join us on Facebook
Please share this news by clicking on one of the icons.
Publisher: Emsisoft GmbH - Mamoosweg 14 - 5303 Thalgau - Austria
CEO: Christian Mairoll - commercial register no.: FN 238178 m

Postagens mais visitadas deste blog

Programação de um CLP: Modos de programação

The Mystery of USB Chargers

Subwoofer Repair