IASI, ROMANIAย โ A new Web-based social engineering attack that relies on malicious Java applets attempts to install backdoors on Windows, Linux and Mac computers, according to security researchers from antivirus vendors F-Secure and Kaspersky Lab.
ย
The attack was detected on a compromised website in Colombia, F-Secure senior analyst Karmina Aquino, said in a blog post on Monday. When users visit the site, they are prompted to run a Java applet that hasnโt been signed by a trusted certificate authority.
ย
If allowed to run, the applet checks which operating system is running on the userโs computer โ Windows, Mac OS X or Linux โ and drops a malicious binary file for the corresponding platform.
ย
The files are detected by F-Secure as โBackdoor:OSX/GetShell.A,โ โBackdoor:Linux/GetShell.Aโ and โBackdoor:W32/GetShell.A.โ Their purpose is to connect to a command-and-control server and look for additional malicious code to download and execute.
ย
However, since F-Secure researchers began monitoring the attack, the remote control server hasnโt pushed any additional code, Aquino said.
ย
It appears that the attack uses the Social Engineer Toolkit (SET), a publicly available tool designed for penetration testers, Aquino said Tuesday via email. However, the chances of this being a penetration test sanctioned by the websiteโs owner are relatively low.
ย
โI donโt think itโs a penetration test,โ Costin Raiu, director of the global research and analysis team at antivirus vendor Kaspersky Lab, said Tuesday via email.
ย
Kasperskyโs researchers are monitoring two separate Web sites that contain this malware, Raiu said. One is the Colombian website also found by F-Secure, while the second belongs to a water park in Barcelona, Spain.
ย
The presence of the malware on a second website in Spain indicates that this attack is not specific to Colombia or a particular entity, Raiu said.
ย
Kasperskyโs researchers are in the process of analyzing the backdoor-type malware downloaded by the malicious shell code on Windows and Linux.
ย
โThe Win32 backdoor is large, about 600KB; the Linux backdoor is over 1MB in size,โ Raiu said. โBoth appear to contact very complex code which communicates encrypted with other servers.โ
ย
This is not the first time that security researchers have discovered a multi-platform attack. In 2010, a similar Java-applet-based social engineering attack capable of executing malicious code on Windows, Mac OS X and Linux computers, was used to distribute the Boonana Trojan program.
ย
โSuch multiplatform attacks indicate the fact that Linux and Mac OS X are becoming interesting targets for cybercriminals,โ Raiu said.
ย
Other malware authors might move to this type of attacks in the future because it allow them to target more users and distribute their creations more widely, Aquino said.
ย