HomeSecurityAngler Exploit Kit | Infected over 90K Sites & continues unabated...

Angler Exploit Kit | Infected over 90K Sites & continues unabated…

The Angler Exploit Kit seems determined to stay... as it has already infected more than 90,000 websites.

The Angler Exploit Kit (AEK) is increasingly increasing its influence on the internet since, according to analyses by Palo Alto Networks, more than 90,000 websites have already been infected by AEK, 30 of which are in the Alexa top 100,000 list.

Angler Exploit Kit | Infected over 90K Sites & continues unabated...

Apparently, the number of monthly visitors to these websites is quite high, probably over 11 million, as estimated by TrafficEstimate.com.

As it appears, this is a highly organized operation in which periodic updates of malicious content are made to all AEK gate sites simultaneously.

https://www.secnews.gr/100441/%cf%80%ce%bf%ce%b9%ce%b5%cf%82-%ce%b5%cf%86%ce%b1%cf%81%ce%bc%ce%bf%ce%b3%ce%ad%cf%82-%ce%b3%ce%b9%ce%b1-%ce%ba%ce%b9%ce%bd%ce%b7%cf%84%ce%ac-%ce%b5%ce%af%ce%bd%ce%b1%ce%b9-%ce%b1%ce%ba%cf%8c%ce%bc/See also: Which mobile applications are still insecure in 2016?

Additionally, infected websites can choose to target specific IP ranges and configurations.
This is why AEK's detection rate is so low, as most of the infected sites were not identifiable even after weeks of study and scanning using VirusTotal scanners.

How does the Angler Exploit Kit evade detection?

The initial version of the AEK malicious JavaScript code was injected into compromised servers and targeted almost all major versions of the Internet Explorer Browser (version 8-11). This is because users have vulnerable versions of Flash installed on their systems.

A new variant of the Angler Exploit Kit can target all advanced, major browsers, even Gecko-based Firefox and Webkit-based Chrome.

Angler Exploit Kit | Infected over 90K Sites & continues unabated...

How does it work?

When the victim visits any of the infected WordPress/Apache hosts, they are immediately redirected to a malicious server where AEK is hosted. This can happen through a middle layer called an EK gate or directly.

https://www.secnews.gr/100411/program-languages-that-generate-most-software-security-bugs/Learn: Which programming language suffers from the most security bugs?

The final malicious payload can vary and can include ransomware such as Cryptowall, spyware or botnets, which can connect the host to a C&C server. This redirection, that is, from the EK gate to the file hosting server, can occur on the same domain or cross-domain.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS