Hackers target human rights websites

2012-05-16 18:24
San Francisco - Internet security researchers warned that foreign policy and human rights websites are being booby-trapped by hackers in what appears to be cyber espionage.

As of Monday websites for Amnesty International Hong Kong, the Cambodian Ministry of Foreign Affairs and the US Centre for Defence Information (CDI) remained rigged to slip "hostile" code onto visitors' computers, according to Shadowserver Foundation devoted to tracking and reporting internet threats.

"These attackers are not spreading malware through strategically compromised websites to make friends," Shadowserver researchers Steven Adair and Ned Moran warned in a blog post.

"They are aiming to expand their access and steal data."

Data typically sought included messages, intellectual property, research, and business intelligence such as contracts and negotiations, according to security specialists.

Tactics

"The CDI website is currently serving up a malicious Flash exploit that ties back to attackers known to engage in cyber espionage," the researchers said.

"This threat group appears to be interested in targets with a tie to foreign policy and defence activities."

In recent weeks, Shadowserver has seen an array of "strategic web compromises" taking advantage of flaws in Oracle Java and Adobe Flash programs.

The tactic is referred to as a "drive-by" attack by computer security specialists because people's computers are secretly infected simply by visiting a reputable website unaware that it has been booby-trapped by hackers.

A website for the International Institute of Counter-Terrorism at the Interdisciplinary Centre in Herzliya, Israel, was listed among those compromised by hackers.

Shadowserver said that it began looking into the hacks after researchers at Websense reported last week that the main page of Amnesty International UK had been rigged with drive-by malware.

There are indications that a website for the American Research Centre in Egypt was briefly compromised last week in a manner similar to the CDI page hack, according to Shadowserver.

Earlier this month the Centre for European Policy Studies website at ceps.eu was similarly compromised, according to the volunteer-based internet security group.

Shadowserver referred to the hacks as "advance persistent threats", a term used in the industry to refer to cyber espionage by groups such as governments.

"Many of these attackers are quite skilled at moving laterally within an organisation and will take advantage of any entry point they have into a network," the researchers said.

"Cyber espionage attacks are not a fabricated issue and are not going away any time soon."
Read more on:    amnesty international  |  cybercrime

Join the conversation!

24.com encourages commentary submitted via MyNews24. Contributions of 200 words or more will be considered for publication.

We reserve editorial discretion to decide what will be published.
Read our comments policy for guidelines on contributions.
NEXT ON NEWS24X

linking and moving

2015-04-22 07:36

24.com publishes all comments posted on articles provided that they adhere to our Comments Policy. Should you wish to report a comment for editorial review, please do so by clicking the 'Report Comment' button to the right of each comment.

Comment on this story
0 comments
Comments have been closed for this article.

Inside News24

 
/News

Book flights

Compare, Book, Fly

Traffic Alerts
There are new stories on the homepage. Click here to see them.
 
English
Afrikaans
isiZulu

Hello 

Create Profile

Creating your profile will enable you to submit photos and stories to get published on News24.


Please provide a username for your profile page:

This username must be unique, cannot be edited and will be used in the URL to your profile page across the entire 24.com network.

Settings

Location Settings

News24 allows you to edit the display of certain components based on a location. If you wish to personalise the page based on your preferences, please select a location for each component and click "Submit" in order for the changes to take affect.




Facebook Sign-In

Hi News addict,

Join the News24 Community to be involved in breaking the news.

Log in with Facebook to comment and personalise news, weather and listings.