April 10, 2008 -- (WEB HOST INDUSTRY REVIEW) -- IT security firm ScanSafe (scansafe.com) says it has found malware on pro-Tibetan independence websites, FreeTibet.org (freetibet.org) and SaveTibet.org (savetibet.org).
Level 1 PCI DSS Certified Service Provider! DataPipe delivers the best network & support; top tier data centers; New York metro, Silicon Valley, London, Hong Kong, Shanghai. DataPipe - Personal Touch, Global Reach.
Visitors to the homepages of these sites will be met with an iFrame that redirects users to a malicious site containing a Trojan downloader.
A Trojan downloader program is usually installed through an exploit or another misleading way, enabling the download and installation of other malware and unwanted software onto the user's PC. It could potentially download adware, spyware or other malware from many servers on the Internet.
The Internet security firm has alerted both websites about the vulnerability, as well has issued an alert notifying Internet users that the sites have been unknowingly hosting malware and infecting visitors by installing the software onto PCs.
Spencer Parker, director of product management at ScanSafe, says:
"These websites appear to have been specifically targeted as this is not a generic Trojan downloader. Someone or some group has gone to great trouble to rewrite the exploit and personalize it to the FreeTibet.org and SaveTibet.org websites.
"ScanSafe threat detection technology found an invisible iFrame which re-directs innocent visitors to a malware-infected site which we have tracked to servers hosted in Taiwan. Given the recent events in Tibet and the protests around the forthcoming Olympics and the Olympic Torch Run, there may be certain groups that are particularly keen to monitor or disrupt activities of pro-Tibet interests.
"Given the world's attention on relations between China and Tibet ahead of the Olympics, it makes sense that these sites would be targeted as Web surfers go online to learn more about Tibet and Tibetan independence. We recommend Web surfers take extreme caution and that all websites review their security policies in the light of these latest developments."
Last week, security firms warned users of April Fools' day-themed emails that may redirect users to maliciously programmed websites.