Hackers turn Bangladeshi embassy website into cryptomining scheme
Full article519 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Almost the entire embassy website appears to be compromised, with nearly every attempt to access a URL ending in a request to save a malicious file.
The websites of foreign embassies are often where people go to download visa applications and other documents. They are also ripe openings for embedding malware.
Criminal hackers have taken notice. In the case of the Bangladesh Embassy in Cairo, attackers appear to be using the website to mine cryptocurrency, according to research published Wednesday by SpiderLabs, the security team of Chicago-based company Trustwave.
Almost the entire embassy website appears to be compromised, with nearly every attempt to access a URL ending in a request to save a malicious file, the researchers said. Only three of 69 antivirus engines detected the infected website as malicious.
“This level of compromise usually indicates the attacker’s ability to not only upload their own data, but also change the web server’s configuration,” SpiderLabs’ Nikita Kazymirskyi wrote in a blog post.
The hackers appear to have breached the website in October. In January, SpiderLabs noticed a Microsoft Word document hosted on the site with an embedded malicious script. Researchers say the hackers are exploiting a known vulnerability in Word that, according to the National Vulnerability Database, allows for remote code execution.
“It is possible that the intruders who injected the web miner into the site decided to make a shift from web mining to machine infection in order to install a more persistent cryptominer on victim machines,” Kazymirskyi wrote.
The hackers don’t seem to be of the advanced persistent threat variety associated with nation-states, Kazymirskyi wrote: they are noisy and the malicious Word file wasn’t tailored to those browsing the website.
As of Wednesday, the Bangladeshi embassy site was still compromised despite the researchers’ efforts to contact the hosts, SpiderLabs said.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/hackers-turn-bangladeshi-embassy-website-into-cryptomining-scheme/