F-Secure researchers have detected a large number of Trojan.JS.Blacole.Gen infections over the past few days, which have been found to be linked to an interesting malware distribution campaign.
According to experts, cybercriminals have hacked a number of websites, 40% of which are German, and added malicious code to them.
When users visit the infected websites, they are redirected to a page that asks them to update Flash Playerin order to access the content.
If the victim clicks on the link, it downloads a file named flashplayer.exe from a SkyDrive account. When the user runs the file, a window appears indicating that the latest version of Flash Player is being installed, while additional malware is also installed.
Additional technical details about the attack can be found on the F-Secure blog.

