Just when you thought it was safe to go back into the Internet Explorer browser waters, a new threat has emerged despite Microsoft’s speedy out-of-band security patch. Symantec has confirmed a new exploit for the security hole used in the recent high-profile attacks against Google and other companies. The new exploit is in the wild and IT administrators who haven’t applied Thursday’s emergency patch are at risk.
The new threat is not the same Trojan.Hydraq malware that was used in the recent attacks against Google.
The malware replaces the code of “MessageBeep API” so that the Internet Explorer process which attempts to play a beep sound will be terminated. After that termination, Symantec said the malware causes the IE window to be displayed again with code to avert API hooking. This can cause some security products to miss some monitored APIs. The result is that a malicious file is downloaded.
Breaches Go Public
“The new exploit is being hosted on hundreds of web sites, and Symantec detects the malicious HTML pages as Trojan.Malscript!html,” said Josh Talbot, security intelligence manager for Symantec Security Response. “The pages contain a shell code that bypasses a warning dialog shown after a downloaded file gets executed.”
Suddenly, the Internet community has become aware of what security experts have always known, said Andrew Storms, director of security operations at nCircle: Breaches like the ones at Adobe Systems and Google happen every day, even to companies with excellent security practices. The only difference here, he said, is that the dimensions and details of this breach are being discussed publicly.
“Probably the most interesting thing about this security event is the absence of participation by the new cyber czar or anyone in the Obama administration. What level of infiltration is required to get the cyber czar off his throne and into the action?”…