Kaspersky website falls victim to malware attack

By

Anti-virus company's website redirected to pages loaded with malware.

Russian security firm Kaspersky has fallen victim to the cyber criminals it tries to protect users against.

Kaspersky website falls victim to malware attack

The company's website - which sells anti-virus software - has admitted it was compromised in an attack on Sunday. Hackers altered the Kaspersky web site such that users trying to download Kaspersky's software were instead redirected to sites loaded with malware.

When duped users reached the destination, they were encouraged to download fake anti-virus software which could compromise their data security.

After initially denying reports posted on online forums, Kaspersky representatives confirmed that attackers had exploited a vulnerability in a third party application used for administrating the security vendor's website.

The company claimed the redirection to the fake anti-virus site only lasted three-and-a-half hours. Further, Kaspersky claimed the affected server was taken offline within ten minutes of being notified.

"Currently the server is secure and fully back online, and Kaspersky products are available for download," the firm said in a statement.

"Kaspersky Lab also wants to confirm that no individual's details were compromised from the company's web servers during this attack.

"Kaspersky Lab takes any attempt to compromise its security seriously. Our researchers are currently working on identifying any possible consequences of the attack for affected users, and are available to provide help to remove the fake antivirus software."

Writing about the incident on his blog, Rik Ferguson, senior security advisor at rival firm Trend Micro said that security vendors "have often been the target of both malicious and mischievous hackers and without fail, honesty and transparency have always been the best policy in the aftermath of such an event."

(Editing by Brett Winterford).

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © ITPro, Dennis Publishing
Tags:

Most Read Articles

Australia's super funds told to assess authentication controls

Australia's super funds told to assess authentication controls

Woolworths' CSO is Optus-bound

Woolworths' CSO is Optus-bound

CBA looks to GenAI to assist 1200 'security champions'

CBA looks to GenAI to assist 1200 'security champions'

Hackers abuse modified Salesforce app to steal data, extort companies

Hackers abuse modified Salesforce app to steal data, extort companies

Log In

  |  Forgot your password?