Slide 50
Slide 50 text
MALWARE AND THE INTERNET
• Almost all modern malware infections, social engineering attempts, phishing and targeted ad
campaigns are now delivered through the Internet
• Attackers compromise high traffic website, inject malicious JavaScript as part of the page or
add an iframe that redirects the user to a phishing site or simply prompts to download and run
“antivirus software”
• The compromise may have been done using a Stored XSS, a weak admin password, server side
code execution vulnerability or due to the usage of a vulnerable library hosted on a CDN
• Attackers also heavily rely on user’s browsing habits, clickbaity articles and user belief in
phishing emails to achieve what is known as a “drive by download” attack
Appsecco – https://appsecco.com @appseccouk