Another Website Poisoning Attack

LOS ANGELES – Hackers have succeeded in poisoning thousands of small e-commerce operations, planting a malicious code that in turn infects visitors to the host website.

Coming on the heels of recent, similar attacks on Flash files and the Real player, the latest of these campaigns also targets computers running Microsoft's Windows operating system, allowing hackers to steal passwords, system information and reports on Internet surfing preferences, along with online bank account information, login names and more.

Estimates vary on the size of the attack, which could have compromised up to 10,000 compromised computer systems.

"It's safe to say that there are thousands of these out there," Yuval Ben-Itzhak, security firm Finjan's CTO, said.

Researchers haven't uncovered all of the new attacks secrets, which they've been monitoring since December, but say that the poisoned websites rely on similar server and administration software.

"We know some of the methods," Ben-Itzhak said. "They are trying to exploit known vulnerabilities in open source content management software that the sites are using."

Many adult websites are driven by content management systems (CMS), which could face similar vulnerabilities to the compromised platforms.

The malicious code hides itself by generating random character names for each unique visitor and by remembering repeat visitors, which are not attacked a second time.

According to Simon Heron, managing director for the security firm Network Box, the attack finds vulnerabilities in common browsing software, and other applications such as instant messaging and multimedia programs, which it can exploit by installing a Trojan that will remain undetected as it waits for sensitive data such as online banking logins to be used.

"It looks like the root kit type technique that we have been worried about for the last two or three years," Heron said. "It's very clever."

Many anti-virus programs fail to detect the presence of the Trojan.

Related:  

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

TTS Opens UK Testing Location

Talent Testing Service (TTS) has opened a new U.K. location in Ware, Hertfordshire.

FSC Responds to Supreme Court Decision on Texas AV Law

The Free Speech Coalition (FSC) has released a statement responding to last week's Supreme Court decision on FSC v. Paxton, the Texas age verification law.

Sex Work CEO Debuts Upgraded 'GPTease' AI Assistant

Sex Work CEO has introduced the new Canvas in-chat editing feature to its AI-powered, NSFW text generator, GPTease.

UPDATED: Supreme Court Rules Against Adult Industry in Pivotal Texas AV Case

The U.S. Supreme Court on Friday issued its decision in Free Speech Coalition v. Paxton, striking a blow against the online adult industry by ruling in support of Texas’ controversial age verification law, HB 1181.

North Carolina Passes Extreme Bill Targeting Adult Sites

The North Carolina state legislature this week ratified a bill that would impose new regulations that industry observers have warned could push adult websites and platforms to ban most adult creators and content.

Supreme Court Ruling Due Friday in FSC v. Paxton AV Case

The U.S. Supreme Court will rule on Friday in Free Speech Coalition v. Paxton, the adult industry trade association's challenge to Texas’ controversial age verification law, HB 1181.

Ofcom: More Porn Providers Commit to Age Assurance Measures

A number of adult content providers operating in the U.K. have confirmed that they plan to introduce age checks in compliance with the Online Safety Act by the July 25 deadline, according to U.K. media regulator Ofcom.

Aylo Says It Will Comply With UK Age Assurance Requirements

Tech and media company Aylo, which owns various adult properties including Pornhub, YouPorn and Redtube, plans to introduce age assurance methods in the United Kingdom that satisfy government rules under the Online Safety Act, the company has announced.

Kyrgyzstan Parliament Approves Measure Outlawing Internet Porn

The Supreme Council of Kyrgyzstan on Wednesday passed legislation outlawing online adult content in the country.

Trial Set for Lawsuit by U Wisconsin Professor Fired Over Adult Content

A trial date of June 22, 2026, has been set for the civil lawsuit filed by veteran communications professor Joe Gow against the University of Wisconsin board of regents, which fired him for creating and appearing in adult content.

Show More