U.S. Department of Labor Site Infected with Malware
According to reports, hackers recently infected the United States Department of Labor website with malware. Security experts have indicated that the attack may have originated in China, since the strategy employed by hackers is very similar to tactics used by Chinese hackers in the past.
The hackers targeted the Site Exposure Matrices (SEM) page within the U.S. Department of Labor website. According to two security firms (AlienVault and Invincea), that page features data related to the storage of toxic substances at United States Department of Energy sites.
Attack May Have Originated in China
Those participating in the attack reportedly used code frequently employed by a Chinese nation-state cyberespionage group known only as "DeepPanda."
This is why some insiders believe the attack came from the Asian country. (Source: darkreading.com)
To compromise the U.S. Department of Labor website's security, the hackers planted code on the main page. This strategy allowed the hackers to redirect website visitors to other pages where their systems could be attacked by malicious software tools.
Attack Exploits Old Internet Explorer Vulnerability
The attack code attempted to detect and exploit Internet Explorer security vulnerability CVE-2012-4792, which has since been patched by Microsoft. (Source: pcworld.com)
Eventually Department of Labor security researchers identified the problem and took the affected pages offline. Reports from security firm Invincea indicate that the problem has now been fixed.
This kind of attack is known in the security world as a "drive-by download". It's one of the most dangerous types of attacks because all someone needs to do in order to become infected is visit a specially-crafted malicious web page.
Once someone's system is infected, the malicious software attempts to contact a command-and-control server. Making a successful connection would then allow hackers remote access to the infected systems.
This isn't the first time we've seen DeepPanda in action. The group was previously responsible for an attack on a number of prominent firms in December 2011.
The United States Department of Labor has not yet commented on this most recent attack.
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.