{"id":1242949,"date":"2022-11-03T16:46:45","date_gmt":"2022-11-03T16:46:45","guid":{"rendered":"https:\/\/www.ghanamma.com\/2022\/11\/03\/crime-group-hijacks-hundreds-of-us-news-websites-to-push-malware\/"},"modified":"2022-11-03T16:46:45","modified_gmt":"2022-11-03T16:46:45","slug":"crime-group-hijacks-hundreds-of-us-news-websites-to-push-malware","status":"publish","type":"post","link":"https:\/\/www.ghanamma.com\/2022\/11\/03\/crime-group-hijacks-hundreds-of-us-news-websites-to-push-malware\/","title":{"rendered":"Crime group hijacks hundreds of US news websites to push malware \u2022"},"content":{"rendered":"<p><\/p>\n<div>\n<p id=\"speakable-summary\">A cybercriminal group has compromised a media content provider to deploy malware on the websites of hundreds of news outlets in the U.S., according to cybersecurity company Proofpoint.<\/p>\n<p>The threat actors, tracked by Proofpoint as \u201cTA569,\u201d compromised the media organization to spread SocGholish, a custom malware active since at least 2018.<\/p>\n<p>The media company in question is not named, but was notified and is said to be investigating. Sherrod DeGrippo, vice president of threat research and detection at Proofpoint, tells  that the organization provides \u201cboth video content and advertising to major news outlets.\u201d DeGrippo added that 250 U.S. national newspaper sites and regional websites are affected, including media organizations serving Boston, Chicago, Cincinnati, Miami, New York, Palm Beach, and Washington, D.C.<\/p>\n<p>It\u2019s unclear how the unnamed media company was compromised, but DeGrippo added that TA569 \u201chas a demonstrated history of compromising content management systems and hosting accounts.\u201d<\/p>\n<p>News of the site hijackings were first <a href=\"https:\/\/twitter.com\/threatinsight\/status\/1587866221847814145\">tweeted out<\/a> Wednesday.<\/p>\n<div class=\"embed breakout\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Proofpoint observed TA569 injects within the assets of a media company used by multiple major news orgs. More than 250 regional\/national newspaper sites have accessed the malicious Javascript. The actual number of impacted hosts is known only by the impacted media company.<\/p>\n<p>\u2014 Threat Insight (@threatinsight) <a href=\"https:\/\/twitter.com\/threatinsight\/status\/1587866221847814145?ref_src=twsrc%5Etfw\">November 2, 2022<\/a><\/p>\n<\/blockquote>\n<\/div>\n<p>The SocGholish malware is injected into a benign JavaScript file that is loaded by the news outlets\u2019 websites, which prompts the website visitor to download a fake software update. In this campaign, the prompt takes the form of a browser update for Chrome, Firefox, Internet Explorer, Edge, or Opera.<\/p>\n<p>\u201cIf the victim downloads and executes this \u2018fakeupdate\u2019 they will be infected by the SocGholish payload,\u201d said DeGrippo. \u201cThis attack chain requires interaction from the end user at two points: accepting the download and executing the payload.\u201d<\/p>\n<p>SocGholish serves as an \u201cinitial access threat,\u201d which if successfully planted have historically served as a precursor to ransomware, according to Proofpoint. The threat actors\u2019 end goal, the company says, is financial gain.<\/p>\n<p>Proofpoint tells  that it \u201cassesses with high confidence\u201d that TA569 is associated with WastedLocker, a variant of ransomware developed by the U.S.-sanctioned Evil Corp group. The company added that it does not believe TA569 is Evil Corp, but rather acts as a broker of already-compromised devices for the hacking group.<\/p>\n<p>It was revealed earlier this year that Evil Corp uses a ransomware-as-a-service model in an effort to skirt U.S. sanctions. The gang was sanctioned December 2019 due to its extensive development of Dridex malware, which the gang used to steal more than $100 million from hundreds of banks and financial institutions.<\/p>\n<\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A cybercriminal group has compromised a media content provider to deploy malware on the websites of hundreds of news outlets in the U.S., according to cybersecurity company Proofpoint. The threat actors, tracked by Proofpoint as \u201cTA569,\u201d compromised the media organization to spread SocGholish, a custom malware active since at least 2018. The media company in [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1242951,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[21],"tags":[],"class_list":["post-1242949","post","type-post","status-publish","format-standard","has-post-thumbnail","category-celebrity-gossip"],"_links":{"self":[{"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/posts\/1242949","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/comments?post=1242949"}],"version-history":[{"count":0,"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/posts\/1242949\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/media?parent=1242949"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/categories?post=1242949"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/tags?post=1242949"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}