Tech News

Tech Business News

  • Home
  • Technology
  • Business
  • News
    • Technology News
    • Local Tech News
    • World Tech News
    • General News
    • News Stories
  • Media Releases
    • Tech Media Releases
    • General Media Releases
  • Advertisers
    • Advertiser Content
    • Promoted Content
    • Sponsored Whitepapers
    • Advertising Options
  • Cyber
  • Reports
  • People
  • Science
  • Articles
    • Opinion
    • Digital Marketing
    • Guest Publishers
  • About
    • Tech Business News
    • News Contributions -Submit
    • Journalist Application
    • Contact Us
Reading: More than 250 newspaper sites across the US access malicious JavaScript in malware supply-chain attack
Share
Font ResizerAa
Tech Business NewsTech Business News
  • Home
  • Technology News
  • Business News
  • News Stories
  • General News
  • World News
  • Media Releases
Search
  • News
    • Technology News
    • Business News
    • Local News
    • News Stories
    • General News
    • World News
    • Global News
  • Media Releases
    • Tech Media Releases
    • General Press
  • Categories
    • Crypto News
    • Cyber
    • Digital Marketing
    • Education
    • Gadgets
    • Technology
    • Guest Publishers
    • IT Security
    • People In Technology
    • Reports
    • Science
    • Software
    • Stock Market
  • Promoted Content
    • Advertisers
    • Promoted
    • Sponsored Whitepapers
  • Contact & About
    • Contact Information
    • About Tech Business News
    • News Contributions & Submissions
Follow US
© 2022 Tech Business News- Australian Technology News. All Rights Reserved.
Tech Business News > Cyber > More than 250 newspaper sites across the US access malicious JavaScript in malware supply-chain attack
Cyber

More than 250 newspaper sites across the US access malicious JavaScript in malware supply-chain attack

Editorial Desk
Last updated: February 5, 2023 11:10 pm
Editorial Desk
Share
SHARE

A threat actor known as TA569 by security experts at Proofpoint have created malicious JavaScript and distributed it to more than 250 regional and national newspaper sites in the US in a malware supply-chain attack

A large number of U.S. news sites have been infected with SocGholish JavaScript malware framework (known as FakeUpdates) due to the compromised infrastructure of an undisclosed media firm.

Security experts at enterprise security firm Proofpoint says 250 U.S. news sites have been infected by the malware.

The threat actor behind the supply-chain attacks (tracked by Proofpoint as TA569) injected malicious code into a benign JavaScript file and then gets loaded by the news outlets’ websites.

In a tweet thread, the Threat Insight unit said the media company that was serving as the host for this malicious code served content to its partners using JavaScript.

The affected media organisations served:

  • Boston
  • New York
  • Chicago
  • Miami
  • Washington DC
  • Cincinnati
  • Palm Beach

VP of threat research and detection at Proofpoint Sherrod DeGrippo, says the media company in affected is a firm that provides video and advertising content to major news outlets.

TA569 historically removed and reinstated these malicious JS [JavaScript] injects on a rotating basis. Therefore the presence of the payload and malicious content can vary from hour to hour and shouldn’t be considered a false positive.” says Proofpoint.

According to the firm Red Canary SocGholish is an initial access threat that leverages drive-by-downloads masquerading as software updates.

In a post about the threat the firm said SocGholish relies on social engineering to gain execution, tricking unsuspecting users into running a malicious JavaScript payload stored within a downloaded ZIP file.

Those who visit compromised websites may be infected with malware payloads disguised as fake browser updates delivered as ZIP archives.

Examples of the devlivered ZIP archives as a result of the malicious JavaScript file are:

  • Chromе.Uрdatе.zip
  • Chrome.Updаte.zip
  • Firefoх.Uрdatе.zip
  • Operа.Updаte.zip
  • Oper.Updаte.zip

SocGholish, recently used to backdoor networks infected with the Raspberry Robin malware was recently used in what Microsoft described as Evil Corp pre-ransomware behavior.

By Editorial Desk
The TBN team is a well establish group of technology industry professionals with backgrounds in IT Systems, Business Communications and Journalism.
Previous Article Game7 and MetaMask web 3 MetaMask Partners with DAO, Game7, to Develop the World’s First Web3-native Game Launcher
Next Article cash converters partners with Nexion Cash Converters partners with Nexion to upgrade its branch office and improve cybersecurity
Leave a comment

Leave a Reply Cancel reply

You must be logged in to post a comment.

U.S. news sites malware supply-chain attack

Tech Articles

Top Cyber Security Threats 2024

Top Cyber Security Threats In 2024

Top cyber security threats in 2024 has put the information…

October 2, 2024
Re-Engagement Campaigns - Inactive Subscribers

Re-Engagement Campaigns To Bring Back Inactive Subscribers

If you’re managing an email list, you’ve probably noticed that…

November 26, 2024
Private Proxy List - The Pirate Bay Download Index

Private Proxy – The Pirate Bay Searchable Online Index For Free Downloads

A private proxy, or personal proxy server, is used exclusively…

September 24, 2024

Recent News

Tech News - Commvault IRAP
Cyber

Commvault Earns IRAP Certification – Australia’s Infosec Registered Assessor Program

4 Min Read
Mandaint changes to Fireeye
Cyber

Mandiant Confirms Name Change from FireEye, Inc. to Mandiant, Inc.

3 Min Read
revil-Russia-jailed
Cyber

REvil group members: Russia detains six more suspects

3 Min Read
Zimperium discovers loan malware flutter apps
Cyber

Zimperium Discovers Novel Predatory Loan Malware In Flutter Apps

4 Min Read
Tech News

Tech Business News

Stay up to date with the latest technology & business news trends from Australia and the around the world.

Technology News reports and whitepaper publishing services are available along with media and advertising options

Our Australian technology news includes People, Business, Science, World News, Local News, Guest publishers, IT News & Tech News Australia | Tech News was established in 2019

About

About Us 
Contact Us 
Privacy Policy
Copyright Policy
Terms & Conditions

December, 10, 2024

Contact

Contact Information.
Melbourne, Australia

Werribee 3030

Phone: +61 431401041

Hours : Monday to Friday, 9am 530-pm.


Tech News

© Copyright Tech Business News 

Latest Australian Tech News – 2024

Welcome Back!

Sign in to your account