New Malware Attack Tries To Trick People By Pretending To Be EFF

from the who-are-they-targeting? dept

The Electronic Frontier Foundation has put out an alert noting that, as part of a larger spear phishing attack campaign, to try to gain control over computers, a group has created a fake EFF website, designed to trick people into thinking they're going to EFF's actual website, but really installing some pretty nasty malware.

Electronicfrontierfoundation.org was not the only domain involved in this attack. It seems to be part of a larger campaign, known as “Pawn Storm”. The current phase of the Pawn Storm attack campaign started a little over a month ago, and the overall campaign was first identified in an October 2014 report from Trend Micro (PDF). The group behind the attacks is possibly associated with the Russian government and has been active since at least 2007.

The attack is relatively sophisticated—it uses a recently discovered Java exploit, the first known Java 0-day in two years. The attacker sends the target a spear phishing email containing a link to a unique URL on the malicious domain (in this case electronicfrontierfoundation.org). When visited, the URL will redirect the user to another unique URL in the form of http://electronicfrontierfoundation.org/url/{6_random_digits}/Go.class containing a Java applet which exploits a vulnerable version of Java. Once the URL is used and the Java payload is received, the URL is disabled and will no longer deliver malware (presumably to make life harder for malware analysts). The attacker, now able to run any code on the users machine due to the Java exploit, downloads a second payload, which is a binary program to be executed on the target's computer.

Needless to say, don't visit the site unless you know what you're doing -- and also, a good reminder not to click on URLs in emails. Go directly to sites.
Hide this

Thank you for reading this Techdirt post. With so many things competing for everyone’s attention these days, we really appreciate you giving us your time. We work hard every day to put quality content out there for our community.

Techdirt is one of the few remaining truly independent media outlets. We do not have a giant corporation behind us, and we rely heavily on our community to support us, in an age when advertisers are increasingly uninterested in sponsoring small, independent sites — especially a site like ours that is unwilling to pull punches in its reporting and analysis.

While other websites have resorted to paywalls, registration requirements, and increasingly annoying/intrusive advertising, we have always kept Techdirt open and available to anyone. But in order to continue doing so, we need your support. We offer a variety of ways for our readers to support us, from direct donations to special subscriptions and cool merchandise — and every little bit helps. Thank you.

–The Techdirt Team

Filed Under: malware, pawn storm, spear phishing
Companies: eff


Reader Comments

Subscribe: RSS

View by: Time | Thread


  • icon
    Goyo (profile), 28 Aug 2015 @ 12:47am

    Did the FBI not did something like this some time ago? For the right reasons, of course.

    link to this | view in chronology ]

  • This comment has been flagged by the community. Click here to show it
    icon
    Sheogorath (profile), 28 Aug 2015 @ 1:46am

    Personally, I wouldn't click on electronicfrontierfoundation.org when I know for a fact it's supposed to be https://eff.org. They've never used the full name in their URL in the time that I've been aware of them, and they adopted automatic encryption about the same time that this site did.

    link to this | view in chronology ]

    • icon
      Sheogorath (profile), 28 Aug 2015 @ 1:48am

      Re:

      It seems the first link is active even though I didn't use tags. Please don't click on it because I don't think it's safe.

      link to this | view in chronology ]

      • icon
        Draph91 (profile), 28 Aug 2015 @ 3:58am

        Re: Re:

        uh dude I'm think of reporting it

        link to this | view in chronology ]

      • icon
        DocGerbil100 (profile), 28 Aug 2015 @ 5:21am

        Re: Re:

        Oh, for fuck's sake.

        Hello, Sheogorath. In the absence of anything else to do about it, I've hit Report. I suggest you and everyone else do the same.

        Dear Techdirt, this page is now permanently serving Russian government malware, until you manually remove or alter the link. Well done.

        As a strategy for dealing with this kind of issue in the longer term, I suggest you learn to FUCKING EDIT BUTTON, already. >:/

        link to this | view in chronology ]

      • icon
        Ninja (profile), 28 Aug 2015 @ 6:02am

        Re: Re:

        I absolutely HATE automagic linking =/

        My sympathies xD

        link to this | view in chronology ]

        • icon
          Sheogorath (profile), 28 Aug 2015 @ 7:29am

          Re: Re: Re:

          I hate it too, especially when there's no need for it because we easily can use tags when we want to turn text into active links.

          link to this | view in chronology ]

      • icon
        ltlw0lf (profile), 28 Aug 2015 @ 8:12am

        Re: Re:

        It seems the first link is active even though I didn't use tags. Please don't click on it because I don't think it's safe.

        I don't see it as a link, but that is probably because I have disabled most of the javascript served up by Techdirt (unless Mike has already removed the tags.)

        Then again, I occasionally submit comments with tags where it strips one or more of the tags (or, far more likely, I break it somehow,) leaving my comment with an unlinked link, but figure that if folks really want to follow it, they can copy and paste.

        link to this | view in chronology ]

        • icon
          Sheogorath (profile), 28 Aug 2015 @ 12:19pm

          Re: Re: Re:

          I don't see it as a link, but that is probably because I have disabled most of the javascript served up by Techdirt [...]
          It's been fixed since.
          [...] (unless Mike has already removed the tags.)
          There weren't any tags in the first place. I used tags on the official EFF website link, yes, but not on the fake EFF website link above it because it was my intention not to link to the fake site at all.

          link to this | view in chronology ]

    • icon
      Draph91 (profile), 28 Aug 2015 @ 3:55am

      Re:

      uh can't you delete it

      link to this | view in chronology ]

  • identicon
    Anonymous Coward, 28 Aug 2015 @ 5:20am

    Can the EFF petition to reclaim that domain name?

    link to this | view in chronology ]

    • icon
      Ninja (profile), 28 Aug 2015 @ 6:03am

      Re:

      I think the registrars can seize and forcefully transfer domains in these cases, can't they?

      link to this | view in chronology ]

      • icon
        Goyo (profile), 28 Aug 2015 @ 6:13am

        Re: Re:

        According to the EFF's post "the phishing domain has been reported for abuse–though it is still active". I guess it just takes some time.

        link to this | view in chronology ]

        • icon
          That One Guy (profile), 28 Aug 2015 @ 6:47am

          Re: Re: Re:

          They should have reported it as involved with copyright infringement, that would have led to it being taken down the same day the report was filed. Phishing though? Eh, they'll get around to it eventually.

          link to this | view in chronology ]

    • identicon
      NO, 28 Aug 2015 @ 5:20pm

      Re:

      EFF is not Hollywood.

      /s

      link to this | view in chronology ]

  • identicon
    Anonymous Coward, 28 Aug 2015 @ 8:02am

    Good reminder, but I have a better one

    also, a good reminder not to click on URLs in emails.
    This is a great reminder not to allow Java applets to run on sites until you understand exactly why you need it. If you are one of those lucky people who never interacts with sites that legitimately need Java, then you should completely block it in the browser.

    link to this | view in chronology ]


Follow Techdirt
Essential Reading
Techdirt Deals
Report this ad  |  Hide Techdirt ads
Techdirt Insider Discord

The latest chatter on the Techdirt Insider Discord channel...

Loading...
Recent Stories

This site, like most other sites on the web, uses cookies. For more information, see our privacy policy. Got it
Close

Email This

This feature is only available to registered users. Register or sign in to use it.