Learn about an example of a supply chain attack where legitimate websites were compromised through websites builders used by creative and digital agencies.
Cyber criminals also target supply chains as a means of reaching the broadest possible audience with their malware. Identifying and compromising one strategically important element is an efficient use of resources and may result in a significant number of infections.
The Shylock banking trojan is as a good example of this. Focused on e-banking in the UK, Italy and the USA, the threat from the group behind this virus was reduced by a joint operation between law enforcement agencies and the cyber-security community, in July 2014.
The Shylock attackers compromised legitimate websites through website builders used by creative and digital agencies. They employed a redirect script, which sent victims to a malicious domain owned by the Shylock authors. From there, the Shylock malware was downloaded and installed onto the systems of those browsing legitimate websites.
The economy of effort makes this a very successful endeavour. By integrating a multitude of different features adopted from other malware, Shylock was capable of performing customisable ‘man-in-the-browser’ attacks, avoiding detection and protecting itself from analysis.
Rather than compromising a number of legitimate sites individually, the attack targeted the core script of a website template designed by a UK-based creative, digital agency.