Blog

Hundreds of U.S. News Outlets Affected by Malware

Nov 11, 2022 | Blog

A cyber-security threat actor known as SocGholish has compromised a JavaScript code used by an unnamed media content provider. The malware is being used to spread the FakeUpdates malware to major media outlets across the United States.

More than 250 regional and national newspaper sites are affected by the malicious JavaScript. Some impacted media organizations include the cities of Boston, Chicago, Miami, and Washington, D.C.

The malware is disguised as a browser update. It is being distributed through advertising networks to hundreds of U.S. news websites. This campaign is particularly severe because it targets the common practice of keeping browsers up to date. Also, with the malware targeting news websites, it can reach a broad audience.

A security research team at Proofpoint Threat Research explained the malware is injected into a JavaScript file that loads on the news outlets’ website on a rotating basis to avoid detection. This prompts the website visitor to download a fake software update for their browser. Due to it rotating through the code, not all website visitors are affected.

What You Might See

When visiting a news site and after the advertising loads, an alert might appear that it is time to update your browser. The messages have been tailored to match the browser, whether you are using Google Chrome, Mozilla Firefox, or Opera. Unfortunately, if downloaded, the file contains malware instead of a security update.

The SocGholish malware serves as an initial access threat. Initial access threats are known to serve as a precursor to ransomware.

How To Prevent Being A Victim

It is easy to authenticate the update notification by navigating to browser settings. Check to see if there are any updates available within the browser controls. Hackers cannot insert their malware links into the browser code. On the other hand, alerts can be triggered by websites and website advertising.

By being aware of what you click on when visiting news websites, you can prevent being a victim of the SocGholish malware. Also, check your browser settings for updates before downloading anything that appears on your screen. Be vigilant when using the Internet since hackers constantly devise new ways to install malware onto unsuspecting victims’ computers.

FBI Program Tasked with Infrastructure Security Compromised

FBI Program Tasked with Infrastructure Security Compromised

The FBI program tasked with ensuring critical infrastructure security has been compromised by hackers, who now offer access to the program's data on the dark web. The breach was initially disclosed by Brian Krebs of Krebs on Security, who claims that the data was for...

Streamline Your Business with the Latest Smart Home Technology

Streamline Your Business with the Latest Smart Home Technology

Are you a business owner looking to get the most out of your Google smart home devices? If so, you're in luck! Google has enabled its Nest products and Android OS with the initial rollout of the Matter smart home standard. This means that businesses now have the...

Data Breach at Sequoia One Exposes Sensitive Customer Information

Data Breach at Sequoia One Exposes Sensitive Customer Information

What do you do when your most personal information has been compromised? This is likely the question that customers of Sequoia One asked themselves earlier this month as they were informed that the company had been hacked. Sequoia One specializes in the management of...

Cisco Reports Critical IP Phone Vulnerability

Cisco Reports Critical IP Phone Vulnerability

As a business owner, it's important to stay informed about potential vulnerabilities that could impact your organization. Recently, Cisco reported a critical vulnerability, tracked as CVE-2022-20968, affecting its IP Phone 7800 and 8800 Series. This new vulnerability...

Google Chrome Releases Two New Features

Google Chrome Releases Two New Features

Google Chrome is one of the more commonly used web browsers. Over the years, though, Chrome has gained a reputation for utilizing a large portion of a computer's memory. This can be a problem if you're running other resource-intensive tasks and don't want to slow...

Get a Free Consultation

 

Fill out the form below to receive a free consultation and learn how we can make your technology worry-free!

 

Contact Information

  • 39301 Badger Street, Suite 500
    Palm Desert, CA 9221
  • (760) 333-8523
  • info@icn.tech