Hackers used previously unknown Internet Explorer flaw in attacks

Published February 14, 2014
Security firm FireEye Inc discovered the attacks against Microsoft Internet Explorer 10 this week. — File Photo
Security firm FireEye Inc discovered the attacks against Microsoft Internet Explorer 10 this week. — File Photo

SAN FRANCISCO: A previously unknown flaw in a recent version of Microsoft Corp's Internet Explorer web browser is being used to attack Internet users, including some visitors to a major site for US military veterans, researchers said Thursday.

Security firm FireEye Inc discovered the attacks against IE 10 this week, saying that hundreds or thousands of machines have been infected. It said the culprits broke into the website of US Veterans of Foreign Wars and inserted a link that redirected visitors to a malicious web page that contained the infectious code in Adobe Systems Inc's Flash software.

FireEye researcher Darien Kindlund said that the attackers were probably seeking information from the machines of former and current military personnel and that the campaign shared some infrastructure and techniques previously attributed to groups in mainland China.

He said planting backdoors on the machines of VFW members and site visitors to collect military intelligence was a possible goal.

A VFW spokeswoman didn't immediately respond to requests for comment.

A Microsoft spokesman said the company was aware of the "targeted" attacks and was investigating. "We will take action to help protect customers," said spokesman Scott Whiteaker.

The latest version of the browser is IE 11, which is unaffected, and a Microsoft security tool called the Enhanced Mitigation Experience Toolkit also protects users who have installed that.

Previously unknown flaws in popular software are a key weapon for hackers and are sold by the researchers who discover them for $50,000 or more, brokers say.

They are most often bought by defense contractors and intelligence agencies in multiple countries, but some of the best-funded criminal groups buy them as well.

Opinion

Editorial

Privatisation divide
14 May, 2024

Privatisation divide

WITH Deputy Prime Minister Ishaq Dar having clawed his way back to the centre of economic policymaking, a tussle...
AJK protests
14 May, 2024

AJK protests

SINCE last week, Azad Jammu & Kashmir has been roiled by protests, fuelled principally by a disconnect between...
Guns and guards
14 May, 2024

Guns and guards

THERE are some flawed aspects to our society that we must start to fix at the grassroots level. One of these is the...
Spending restrictions
Updated 13 May, 2024

Spending restrictions

The country's "recovery" in recent months remains fragile and any shock at this point can mean a relapse.
Climate authority
13 May, 2024

Climate authority

WITH the authorities dragging their feet for seven years on the establishment of a Climate Change Authority and...
Vending organs
13 May, 2024

Vending organs

IN these cash-strapped times, black marketers in the organ trade are returning to rake it in by harvesting the ...