- MPack (software)
In
computer security , MPack is aPHP -basedmalware kit produced by Russian crackers. The first version was released in December 2006. Since then a new version is thought to have been released roughly every month. It is thought to have been used to infect up to 160,000 PCs with keylogging software. In August 2007 it was believed to have been used in an attack on the web site of theBank of India which originated from theRussian Business Network .Unusually for such kits, MPack is sold as commercial software (costing $500 to $1,000 US), and is provided by its developers with technical support and regular updates of the software vulnerabilities it exploits. Modules are sold by the developers containing new exploits. These cost between $50 and $150 US depending on how severe the exploit is. The developers also charge to make the scripts and executables undetectable by
antivirus software .The server-side software in the kit is able to customize attacks to a variety of
web browser s includingMicrosoft Internet Explorer ,Mozilla Firefox and Opera. MPack generally works by being loaded in anIFrame attached to the bottom of a hacked website. When a user visits the page, MPack sends a script that loads in the IFrame and determines if any vulnerabilities in the browser or operating system can be exploited. If it finds any, it will exploit them and store various statistics for future reference.Included with the server is a management console, which allows the attacker deploying the software to view statistics about the computers that have been infected, including what web browsers they were using and what countries their connections originated from.
Experts at Spy-Ops have estimated that the market for hacker toolkits such as MPack has exploded into hundreds of millions of dollars USD annually.
References
* cite web
url=http://news.bbc.co.uk/1/hi/technology/6221306.stm
title=Hackers target 'legitimate' sites
publisher=BBC
date=2007-06-20
accessdate=2007-06-26
* cite web
url=http://www.symantec.com/enterprise/security_response/weblog/2007/05/mpack_packed_full_of_badness.html
title=MPack, Packed Full of Badness
publisher=Symantec
date=2007-05-27
accessdate=2007-06-26
* cite web
url=http://blogs.pandasoftware.com/blogs/images/PandaLabs/2007/05/11/MPack.pdf
title=PandaLabs Report: MPack uncovered
publisher=PandaLabs
date=2007-05-11
accessdate=2007-07-04
* cite web
url=http://www.theregister.co.uk/2007/07/03/mpack_reloaded/
title=MPack malware exposes cheapskate web hosts
publisher=The Register
date=2007-07-04
accessdate=2007-07-04
* cite web
url=http://www.theregister.co.uk/2007/07/23/mpack_developer_interview
title=Interview with MPack developer
publisher=The Register
date=2007-07-23
accessdate=2007-07-23
* cite web
url=http://blog.washingtonpost.com/securityfix/2007/10/mapping_the_russian_business_n.html
title=Mapping the Russian Business Network
author=Brian Krebs
publisher=Washington Post blogs
date=2007-10-13
accessdate=2007-10-14
* cite web
url=http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9033999
title=Bank of India site hacked, serves up 22 exploits
author=Gregg Keizer
publisher=Computer World
date=2007-09-31
accessdate=2007-10-14
Wikimedia Foundation. 2010.