The Tech Herald

Insider arrested after DNS-poisoning attack targets Brazilian ISPs

by Steve Ragan - Nov 7 2011, 15:57

A 27-year-old employee of a medium-sized ISP in the southern part of Brazil has been arrested, after a DNS cache-poisoning attack spread across the country and pointed millions of users to a Trojan aimed at capturing banking and other credentials.

Last week, millions of Brazilians had their Internet connections hijacked, prompting them to install malicious software after visiting popular destinations such as Hotmail, Gmail, YouTube, and local portals Uol, Terra, and Globo.

Kaspersky’s Fabio Assolini reported on the attacks and noted that users were being told to install a banking Trojan, disguised as a security program called 'Google Defense'

“Last week Brazil’s web forums were alive with desperate cries for help from users who faced malicious redirections when trying to access websites such as YouTube, Gmail and Hotmail, as well as local market leaders including Uol, Terra and Globo,” he said.

“[Redirected users were asked] to download and install the so-called “Google Defence” software required to use the search engine. In reality, though, this file is a Trojan banker detected by Kaspersky’s heuristic engine. Research into this IP highlighted several malicious files and exploits hosted there.”

As mentioned, Brazil’s Federal Police arrested an employee of a medium-sized ISP in the southern part of the country. It’s understood that, for a period of around 10 months, he used his access to alter the company's DNS cache, which, in turn, forced its customers toward a malicious server handing out the banking malware.

Kaspersky suspects that similar internal compromises are also happening across Brazil.

In related news, businesses across the country were reporting that their networking equipment, such as modems and routers, were remotely compromised and their DNS settings had been changed in order to join the attack.

Corporate users were redirected to the malicious server and told to install a Java applet, which in fact was another variant of the aforementioned banking Trojan.

“We advise all affected users to update antivirus and all software in the computer (such as Java), also change the DNS configuration to other providers (such as Google DNS). In attacks against network devices we also recommend updating the firmware of the router and changing the default passwords,” Assolini encouraged.

The attack's exact number of victims is unknown, but there are an estimated 73 million devices connected to the Internet in Brazil, and the top ISPs in the country manage about 3-4 million people each. So, even if only a small percentage were successfully targeted, the overall total number of victims is likely to be frightening.

Around the Web

Comment on this Story

comments powered by Disqus

From Autosaur.com

Monaco Grand Prix Circuit Map

Infiniti Red-Bull have released a Monaco Grand Prix circuit map showing a string of G-Force and speedo readings recorded in their cars on a normal lap. The team also described the most complicated turns on the track: Turn 1, Sainte Devote, sees drivers hit the barrier if they come into corner just 1km/h too fast [...]

The post Monaco Grand Prix Circuit Map appeared first on Autosaur.

Daniel Day-Lewis and Yasmin Le Bon at Mille Miglia rally in Italy

Jaguar have released a cool little film about their experience at this year’s Mille Miglia car rally in Italy — featuring stars including triple Oscar-winner Daniel Day-Lewis and model Yasmin Le Bon. The video has short interviews with several of the famous participants about taking part in the 1,000-mile event, which celebrates the original Mille [...]

The post Daniel Day-Lewis and Yasmin Le Bon at Mille Miglia rally in Italy appeared first on Autosaur.

Man wins Batman version of Nissan Juke

A BATMAN fan has won a special version of the Nissan Juke inspired by the films — and which has a string of features more normally seen on the Batmobile. Adam Williams was presented with the matt black vehicle after a real Batmobile (well, as real as they get) was driven through the streets of the [...]

The post Man wins Batman version of Nissan Juke appeared first on Autosaur.