HomeCommunitySecurity Blog

Security Blog

 

Gumblar: One Week Later

Posted By Pete at 5:48 PM, May 29, 2009

A week ago Gumblar officially became a major threat. You can read our report on Gumblar here (or just scroll down and look at the previous blog entry). Since then, it has only become more intrusive and evasive. The virus has shown no signs of slowing down. Although the original domains gumblar.cn and martuz.cn have been shutdown, new ones such as liteautotop.cn and autobestwestern.cn have taken their place. The injected scripts are now dynamically generated and created in a way to bypass virus scanner detection.

What Gumblar has shown us is how vulnerable we are against Web-based malware attacks. This along with Youtube, Facebook targeted malware is a clear indication that cyber criminals have shifted their focus to the Web. It's not just the anti-malware or data leak prevention technology that is having a hard time stopping Gumblar, but also the unawareness of your regular Joe as he is doing a Google search or browsing the Web. The Web is a dangerous place but the general public does not know that yet. that will be the biggest challenge for all of us to overcome moving forward.

Posted by: Pete at 5:48 PM
Categories: Malware , Viruses

No TrackBacks

TrackBack URL: http://prosecure.netgear.com/cgi-bin/mt/mt-tb.cgi/25

Comments