Multi-Middleman 'Mpack' Attacks Use Google AdWords to Lure Victims

By Scott M. Fulton, III | Published June 19, 2007, 11:46 AM

One of Russia's fastest growing markets, and quite possibly a contributor to stabilizing that country's fickle economy, is cut-rate, self-deploying Trojan horse packages.

As malware writers there have discovered, rather than baiting and waiting for victims to fall into their traps at random, so that they carry out DoS and identity theft attacks without knowing they're doing so, would-be victims worldwide will gladly pay for the privilege of knowingly carrying out those same attacks.

"In terms of social engineering," writes Trend Micro researcher Carolyn Guevarra, "it seems the authors behind this attack have come up with the perfect crime."

For a few hundred dollars, maybe less, people who seek the vicarious thrill of serving as tools for fake Russian mobsters are downloading the "Mpack" package. They then install it on their own systems and monitor their screens as a startlingly efficient admin toolkit of sorts charts the flags of various target countries, like a real-time game of "Risk."

As a report from anti-virus company Trend Micro states this morning, the target of choice for Mpack in recent days has been Italy. Many of its higher-profile sites have been targeted in recent days, including media publishers, tourism services, and auto sales sites.

But it may be inaccurate to say that the Russians are directly targeting the Italians, since according to in-depth analyses of Mpack, it's the customers who purchase Mpack from underground Russian servers who decide which Web sites will be the unsuspecting hosts of attacks on their users.

The attacks themselves are not new, though they are surprisingly varied. According to an in-depth report from Panda Software security engineer Vincente Martinez (PDF available here) which stops just short of telling you where you can buy the thing yourself, servers infected with the Mpack downloader can then install Trojan packages on unsuspecting users' computers. The methodology for this distribution is not brute-force; in fact, it appears to try several approaches specifically tailored for the victim's browser - IE7, Firefox, or Opera. (Yes, these are Windows-based attacks.)

A browser pointed to one of many targeted Italian Web sites is tricked by Mpack into downloading malicious JavaScript code, often by way of a well-known exploit: inline code within an invisible <IFRAME> element that redirects the browser to a raw IP address. That address can then use any of multiple methods, including buffer overflow, to upload stealth code through the browser, onto the victim's machine. From there, Panda's engineers reveal, statistics can be gleaned from that machine, and compiled into a format compatible with MySQL.

Those statistics may then be returned to the Mpack customer, who may or may not have any use for them anyway - he might not even know what they mean. Whether a separate report is produced for Mpack's own writers is unknown.

But the Panda report also states that Mpack's writers an extremely unorthodox approach to amplifying the magnitude of their attacks, which customers may perceive as a unique "value-add:" Along with the invisible <IFRAME> element, they inject non-displayed words into the HTML code of sites' front pages - perhaps words that may not have anything to do with the sites' native contexts. Then they use a portion of their income from sales to purchase sponsored links from Google AdWords, matching those words with users' searches to direct them to those sites. (Hypothetical example: "More about Paris Hilton in jail at UsedFerraris.it")

A report from Virus Bulletin this morning estimates the number of Mpack-infected servers worldwide to have risen just over the weekend to over 10,000, with Italy housing the majority. Trend Micro points out that Mpack's writers could conceivably update their Trojan-implanting server (the one to which the <IFRAME> element directs browsers) without actually having to update the software they sell, which could make heuristics for tracking Mpack's behavior even more difficult to construct.

Comments

View comments by with a score of at least

Google Adwords is the best way to get traffic to your site, legit or otherwise.

Odd the discusion is about Google and not the 10000 cracked IIS servers or the fact that there has never been a single day when it was safe to brouse the web with a Windows PC.

If you must use Windows use firefox with the noscript plug-in. Only allow sites you know and trust to run scripts on your machine. I like to check and make sure they are running apache before I enable their scripts.

Score: 0

|

true.
somtimes having a heavily virus infected machine, is even lighter than having a scanning mcafee or norton.

Score: 0

|

There is more incentive to develop malware in today's society than there is to develop anti-malware. So--we still wonder why it's so hard to find a decent anti-virus program these days...

Score: 0

|

Every Anti-virus program is a reactive technology... and by that model is subject to flaws, both false positive and delayed reaction to real-world threat.

Which leads one to the conclusion: There is no point using AV over meticulously managing your routers, firewalls, client and server operating systems and training your staff/friends/self on safe browsing/computing, (which of course means always browse with lower privilege levels, something linux and OSX people have done for many years before vista came around.)

Score: 0

|

'A pivot from war to peace:' The AMD + Intel armistice, in their own words

An extraordinary day in technology history is recognized by two long-time rivals that mutually decided it's futile to fight anyplace else except the marketplace.

PS3, Xbox to soon get Twitter, Facebook integration

Both Microsoft's Xbox 360 and Sony's PlayStation 3 will integrate with Facebook in the near future.

Windows Marketplace for Mobile now available in browser, iTunes' App Store still not

You can now check out what Windows Marketplace for Mobile has to offer without a Windows Phone.

Microsoft damage control after marketer claims Win7 inspired by Mac

Have you ever said anything you wish you could take back? Ever? No? Not even once? Well then, you won't sympathize with a mid-level Microsoft manager today.

Blockbuster's way down, but poised for a comeback

Though it took a serious beating in 2009, Blockbuster CEO Jim Keyes says the company can turn it around.

iTunes Preview deson't go far enough to create Web-based option for store

Apple has rolled out iTunes Preview, a Web interface for browsing iTunes.

PDC 2009 Preview: The move to Office 2010 and Visual Studio 2010

The major focus of Microsoft's conference next week will likely be explaining why two pillars of its software sales strategy deserve to remain where they are.

Dell's first smartphone aids the Android onslaught

Longtime PC leader Dell has finally announced its Android-based smarphone.

After the Intel + AMD armistice: Do we really want a level playing field?

Scott Fulton On Point: One by one, the reasons for us to continue suspending the course toward open and fair competition in IT, are dropping like flies.

FLO TV launches pocketable, smartphone-like TVs

Qualcomm's FLO TV Personal Television made by HTC launches in retail today.

Google acquires Gizmo5, builds IP telephony portfolio

Google Voice today confirmed rumors that it would acquire IP telephony company Gizmo5