The Electronic Frontier Foundation (EFF) has cautioned people of the domain electronicfrontierfoundation.org that has been said to be responsible for the phishing attack since Aug. 4. The domain is said to have been registered on that same day.
Google’s security team discovered the spear phishing attack, and is said to be part of a larger effort called “Pawn Storm” discovered a year ago. Trend Micro is said to have discovered this. This time around with the phishing attack, it exploits a Java vulnerability.
For instance, a target would receive an email with a link form that contains the electronicfrontierfoundation.org domain on it. This has a Java applet riding on it, which in turn then begins to exploit this vulnerability.
After the first go, class payload has been dropped off, it goes about then until it has achieved full control upon which its second load, the app class is released. This is the one which then exploits the Java vulnerability.
Then, a second stage binary, comac.mcr, is used to detect what operating system the intended target is using. From there, the attacker then uses the necessary file or program to infect the target computer.
Such attacks happen every now and then and usually pinpointing its exact origin is hard. Even though the said attack can be traced back to a source, it is possible that the attackers have already covered their tracks and would deliberately mislead people by pointing to an equally fake source. This is so that they can operate once again and make an attack without getting caught.
Usually those who do such things have been doing it for years and have known how to protect themselves, so to speak. Users, in turn, should always be on guard about such things. The usual caveat is always the best, which is not to open any link that seems suspicious or unfamiliar since chances are it is a cyber attack.
Installation of protection like a malware, spyware and virus detector can also help. Although most people will have programs that can detect such things, many as well often fail to update their database and regularly check their systems.
