Amnesty HK site visitors were slugged with IE zero day

‘Similar’ to Tencent-signed malware attack on Amnesty UK, says Symantec.
  • Liam Tung (CSO Online (Australia))
  • — 19 June, 2012 11:18

The zero day Internet Explorer (IE) attack McAfee discovered on June 1 was aimed at visitors of Amnesty International’s Hong Kong website, says Symantec.

The attackers injected an iframe into Amnesty’s Hong Kong site pointing to a Russian domain that hosted a JavaScript file. That file exploited the IE flaw, according to Symantec’s Security Response team.

Users exposed to the attack would have been presented with an error message stating the site was “under construction” while the exploit installed a downloader and backdoor trojan, which Symantec labels “Trojan.Naid”.

Symantec said it had seen Niad as early as January 2010, but only added a signature for it this week after McAfee researchers disclosed the vulnerability for Microsoft to patch.

Microsoft patched the flaw (CVE-2012-1875) in last week's security bulletin, which affected IE 6 through 9 across multiple versions of Windows.

Naid collects the domain names a user visits and their device’s unique identifier, and allows the attacker to issue remote commands to the PC over a proprietary protocol, said Symantec.

The exploit “seems to be very reliable” and the payload pointed to command and control servers hosted by Chinese ISP, China Shenzen Soul Tech, according to an analysis by Security firm AlienVault.

Symantec said the iframe has now been removed from Amnesty’s Hong Kong site, noting the attack's similarity to the one aimed at Amnesty International’s UK website visitors last month.

In that case, the certificate for the executable file was signed by Chinese ISP Tencent. The certificate had been in use for some time and did not appear to be revoked at the time of those attacks, according to Websense.

Amnesty’s Hong Kong site was last rigged in 2010, that occasion also involving an IE zero day to target users with malware.

Follow @CSO_Australia and sign up to the CSO Australia newsletter.

Comments are now closed.
CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Access Risk Management Suite

The Access Risk Management Suite enables organizations in industries across the board, to improve security, corporate and regulatory compliance and increase operational efficiency.

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.