Poisoned websites attack visitors

Thousands of small web shops have been unwittingly poisoned with malicious code that infects PC users who visit. Security experts said the sophisticated attack had succeeded on a larger scale than many other similar attacks.

Once installed on a Windows machine the malicious code steals passwords, browser data as well as login names for bank accounts and online games. The attack is proving hard to defend against for both sites being hit and PC users who are caught out.

Big hitter

Security researchers at ScanSafe, Finjan and Secure Works separately discovered the nest of poisoned websites. Estimates of how many sites have been enrolled into the attack vary. ScanSafe said it knew of about 230 but Secure Works and Finjan believe the total could be as high as 10,000.

Yuval Ben-Itzhak, chief technology officer of Finjan, said it had been following the attack since early December when it noticed an increase in the number of attacks using poisoned websites.

