Ars Technica compromised. Come read the story at Ars Technica!
Technology
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related content.
- Be excellent to each another!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, to ask if your bot can be added please contact us.
- Check for duplicates before posting, duplicates may be removed
Approved Bots
I guess it's less that the site was compromised, and more that someone linked an image in their account bio? It only worked on victims already infected with the first stage (not that I understand what happened there)
Waiting for the
If you saw this pizza, you(r computer) might be infected
Oh shit oooops
It’s also not clear that any Ars users visited the about page.
Are weblogs not a thing? They should be able to tell how many times that page was accessed and by whom with a single query.
It's complicated. It's possible that their web server does have these logs but they might not go into the database, and when you're a large website you might not have logs collected centrally simply because you generate so much data.
Damn, that's pretty cool actually.
This is the best summary I could come up with:
Ars Technica was recently used to serve second-stage malware in a campaign that used a never-before-seen attack chain to cleverly cover its tracks, researchers from security firm Mandiant reported Tuesday.
A benign image of a pizza was uploaded to a third-party website and was then linked with a URL pasted into the “about” page of a registered Ars user.
The campaign came from a threat actor Mandiant tracks as UNC4990, which has been active since at least 2020 and bears the hallmarks of being motivated by financial gain.
Opening the same file in a hex editor—a tool for analyzing and forensically investigating binary files—showed that a combination of tabs, spaces, and new lines were arranged in a way that encoded executable code.
The base 64 strings in the image URL or video description, in turn, caused the malware to contact a site hosting the second stage.
Anyone who is concerned they may have been infected by any of the malware covered by Mandiant can check the indicators of compromise section in Tuesday’s post.
The original article contains 675 words, the summary contains 173 words. Saved 74%. I'm a bot and I'm open source!