HomeSecurityOrganized cyber campaign targets industrial, government and financial entities via IE...

Organized cyber campaign targets industrial, government and financial institutions via IE Exploit

Organized cyber campaign targets industrial, government and financial institutions via IE Exploit

The most recent zero-day vulnerability discovered in Internet Explorer (CVE-2013-3897) has now been patched by Microsoft. However, security experts note that cybercriminals have been using the IE exploit in targeted attacks since at least August 23, 2013.

According to security researchers at Websense, a cybercriminal organization exploited the browser vulnerability to carry out highly targeted, low-intensity attacks.

The attacks were carried out against organizations specializing in the engineering and construction sectors (33%), financial and financial organizations (33%), industrial and manufacturing units (17%), and government agencies (17%).

Experts found that all attacks originated from specific IP addresses located in Korea. Furthermore, the websites used as bait to carry out the attacks all have the same URL pattern.

Interestingly, these pages were designed to check whether the language of the victim's operating system is set to Japanese or Korean before executing the exploit.

The most targeted countries according to experts are the USA (50%), the Republic of Korea (33%) and Hong Kong (17%).

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS