Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Hacked Texas National Guard site serves up malware

By Gregg Keizer , Computerworld , 09/19/2008
Newsletter Signup
  • Share/Email
  • Tweet This
  • Comment
  • Print

Attackers have hacked the Web site of the Texas National Guard and are using it to serve up offers of fake security software and plant rootkits on unpatched PCs, a security researcher said Thursday.

The Guard's site was hacked sometime before Wednesday, said Roger Thompson, the chief research officer of Czech Republic-based security vendor AVG Technologies. Thompson confirmed Thursday that the site was still pushing phony anti-spyware software and infecting users with a rootkit.

"It's still infective," Thompson said Thursday in an instant message exchange. "I did a refresh and [it] whacked me."

A spokeswoman for the Guard, Chief Master Sergeant Gonda Moncada, acknowledged the hack mid-day. "We are aware of the situation and are working hard to fix it," she said in an e-mail.

According to Thompson's original analysis, malicious code planted on the Guard site sends the visitor's browser to the hacker site. "[That's] probably in Russia," said Thompson, "[but I] can't confirm it, because the ISP for the host is not answering whois queries."

The malicious site tries to trick users into forking over money for fake security software, said Thompson. "If you're not patched, when you close your browser, you find that your desktop has changed," he said, referring to a pop-up message that claims the user's PC is infected with spyware.

"This machine is now hopelessly nailed, and code has been installed in the background, and their pitch is that they'll remove it for a mere [US]$49.95, and insert your credit card number here, please," said Thompson.

In the background, the attackers also plant a rootkit, software that hides malware to make it tougher for legitimate security software to sniff out and snuff attack code.

Moncada did not respond to other questions, including when the site would be cleansed of the malicious code and how it had gotten onto the site.

  • Share/Email
  • Tweet This
  • Comment
  • Print
Comments (1)
Login
Forgot your account info?

THE BIG UGLY BEAR SCAREBy Anonymous on September 20, 2008, 10:38 amMore Bullshit and propaganda for the upcoming inet 911 that will be used as an excuse to lock down the internet and take away more of our freedoms. IT'S THE RUSSIANSSSSSSSSSS...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed