You are viewing 'Cridex'


Into the Blackhole

Jeremy Scott

Jeremy Scott    |    August 21, 2012

The latest news in malware has been the recent Kaspersky Labs discovery of the sophisticated attack toolkits named Gauss. Headlines also include reports of the Zegost RAT being served by compromised Nepalese government websites. However, the majority of the malware samples received the last couple of weeks have been related to the Blackhole Exploit Kit.

The Solutionary SERT research team has been tracking this issue for some time and our public reports up to this point have been relatively high-level. If what we’ve observed over the past few weeks is any indicator, Blackhole will not be going away any time soon, and it... read more >



Tags: Blackhole Exploit Kit, malware, phishing, vulnerabilities, vulnerability, Gauss, Trojan, Zegost RAT, Cridex

Rejected Wire Transfer Leads to Blackhole Exploit Kit

Jeremy Scott

Jeremy Scott    |    July 19, 2012

The Solutionary Security Engineering Research Team (SERT) has been receiving a significant amount of malicious emails luring would-be victims to hosts running the Blackhole Exploit Kit.

The emails claim to be related to a rejected wire transfer. SERT has observed that the malicious emails use an embedded hyperlink or an attached HTML file attachment. The hyperlink points to a compromised website, usually running a piece of obfuscated javascript that is decoded as an iframe. The iframe redirects the victim’s browser to a Blackhole landing page that attempts to exploit the victim’s computer and install additional malware such as... read more >



Tags: Blackhole Exploit Kit, Cridex, email scam, malicious emails, malicious hosts, malware, managed security service provider, security best practices, security intelligence, spam, toolkit, Trojan, email security, Gameover Zeus, malicious sites

Solutionary is a leading managed security service provider. The company reduces the information security and compliance burden, providing flexible security services that work the way clients want; enhancing existing initiatives, infrastructure and personnel. This blog is a place to learn about, and discuss, a wide variety of security and compliance topics.

Subscribe Now!  RSS Feed

LATEST TWEETS