Russians behind attack PDFs, security researcher says

An infamous hacker gang is sending malicious PDF docs, stealing financial data

A notorious Russian hacker gang is responsible for ongoing attacks using malicious PDF documents, a researcher said Wednesday.

Users can thank the Russian Business Network (RBN), a well-known collective of cybercriminals, for the malware-armed PDF attachments that began appearing in in-boxes Tuesday, said Ken Dunham, director of response for iSight Partners. If the rigged PDFs succeed in infecting the target Windows system, the attack code installs a pair of rootkit files that "sniff and steal financial and other valuable data," said Dunham via e-mail.

The rogue PDF documents are attached to spammed e-mail and arrive with filenames such as BILL.pdf, YOUR_BILL.pdf, INVOICE.pdf or STATEMET.pdt, said Symantec in a separate advisory Tuesday. They exploit the "mailto:" protocol vulnerability disclosed more than a month ago by U.K.-based researcher Petko Petkov.

When recipients open the attacking PDF, it launches a Trojan horse dubbed "Pidief.a" that knocks out the Windows firewall and then downloads another piece of malware to the compromised computer. That second piece of attack code is a dedicated downloader that, in turn, retrieves the two rootkit files from a pair of RBN-controlled servers and drops them onto the hacked PC.

According to Dunham, the RBN servers and the rootkit files are familiar to researchers. "[They] are the same as those used in zero-day Vector Markup Language (VML) attacks from September 2006," he said. The VML vulnerability, disclosed early that month, was so aggressively exploited that a group of security professionals issued an unsanctioned patch, prompting Microsoft to release one of its rare out-of-cycle fixes in late September.

Adobe Systems fixed the flaw Monday and released updated 8.1.1. editions of both Reader and Acrobat that plug the hole. Users of older versions of the popular programs must either upgrade to 8.1.1 or apply one of the temporary work-arounds that Adobe provided to stifle attacks. On Monday, Adobe did say that it would update Adobe Reader 7.0.9 and Acrobat 7.0.9 "at a later date," but it did not set a definitive timeline.

Although Adobe patched the newest versions of Reader and Acrobat, the vulnerability is ultimately Microsoft 's responsibility. The software vendor owned up to that two weeks ago, saying that it would patch common protocol handlers such as "mailto:" in Windows XP and Windows Server 2003.

Only users running the Internet Explorer 7 browser on Windows XP or Windows Server 2003 are vulnerable to the PDF exploit.

Adobe's security bulletin includes links to the Adobe Reader and Acrobat updates.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Gregg Keizer

Computerworld
Show Comments

Cool Tech

SanDisk MicroSDXC™ for Nintendo® Switch™

Learn more >

Breitling Superocean Heritage Chronographe 44

Learn more >

Toys for Boys

Family Friendly

Panasonic 4K UHD Blu-Ray Player and Full HD Recorder with Netflix - UBT1GL-K

Learn more >

Stocking Stuffer

Razer DeathAdder Expert Ergonomic Gaming Mouse

Learn more >

Christmas Gift Guide

Click for more ›

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Walid Mikhael

Brother QL-820NWB Professional Label Printer

It’s easy to set up, it’s compact and quiet when printing and to top if off, the print quality is excellent. This is hands down the best printer I’ve used for printing labels.

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?