Skip to main content

Pro-ethical hacking group hacked, used as malware front

ethical hacker site hacked ransomware eccouncil
FOX IT
The administrators of the Certified Ethical Hacker (CEH) program, which looks to spread knowledge and know-how about measures to prevent being hacked, has come under fire from security organizations for its own lax security and its late response to related warnings. Despite being provided with ample notice, the CEH ignored warnings that it was distributing malware to some of its visitors.

Admittedly, the hack in question was an elusive one. According to a FOX IT report, the Angler toolkit which had infected the site would further infect those who visited the site from a major search engine and were using Internet Explorer — likely suggesting a less than stellar knowledge of Internet security.

What’s heartbreaking is that the visitors were themselves clearly trying to learn — they were, after all, looking up courses on improving security.

But unfortunately the very site they visited was the one making the visitors vulnerable. So now a security firm has gone public (via Ars) with the information, in the hopes that it encourages action and discourages people from visiting the site until it’s safe again.

Related: Update: Mac ransomware may have flaws that allow file recovery

The notice states visitors who meet the criteria for infection may find themselves redirected  to the Angler toolkit landing page, which then uses Flash or Silverlight plugins to infect the victim’s local machine with more malware.

Most worrisome is that the malware it then dumps on the user’s system is TeslaCrypt, a ransomware that immediately encrypts the user’s files and demands a 1.5 bitcoin ransom (equal to around $624) to decrypt them — potentially meaning that visitors to the CEH site could lose all of their important and personal files and images.

The malware program is very traditional too, offering just the payment option — unlike others, there is no offer to sign on as an affiliate.

Editors' Recommendations

Jon Martindale
Jon Martindale is the Evergreen Coordinator for Computing, overseeing a team of writers addressing all the latest how to…
4 CPUs you should buy instead of the Ryzen 7 7800X3D
AMD Ryzen 7 7800X3D sitting on a motherboard.

The Ryzen 7 7800X3D is one of the best gaming processors you can buy, and it's easy to see why. It's easily the fastest gaming CPU on the market, it's reasonably priced, and it's available on a platform that AMD says it will support for several years. But it's not the right chip for everyone.

Although the Ryzen 7 7800X3D ticks all the right boxes, there are several alternatives available. Some are cheaper while still offering great performance, while others are more powerful in applications outside of gaming. The Ryzen 7 7800X3D is a great CPU, but if you want to do a little more shopping, these are the other processors you should consider.
AMD Ryzen 7 5800X3D

Read more
Even the new mid-tier Snapdragon X Plus beats Apple’s M3
A photo of the Snapdragon X Plus CPU in the die

You might have already heard of the Snapdragon X Elite, the upcoming chips from Qualcomm that everyone's excited about. They're not out yet, but Qualcomm is already announcing another configuration to live alongside it: the Snapdragon X Plus.

The Snapdragon X Plus is pretty similar to the flagship Snapdragon X Elite in terms of everyday performance but, as a new chip tier, aims to bring AI capabilities to a wider portfolio of ARM-powered laptops. To be clear, though, this one is a step down from the flagship Snapdragon X Elite, in the same way that an Intel Core Ultra 7 is a step down from Core Ultra 9.

Read more
Gigabyte just confirmed AMD’s Ryzen 9000 CPUs
Pads on the AMD Ryzen 7 7800X3D.

Gigabyte spoiled AMD's surprise a bit by confirming the company's next-gen CPUs. In a press release announcing a new BIOS for X670, B650, and A620 motherboards, Gigabyte not only confirmed that support has been added for next-gen AMD CPUs, but specifically referred to them as "AMD Ryzen 9000 series processors."

We've already seen MSI and Asus add support for next-gen AMD CPUs through BIOS updates, but neither of them called the CPUs Ryzen 9000. They didn't put out a dedicated press release for the updates, either. It should go without saying, but we don't often see a press release for new BIOS versions, suggesting Gigabyte wanted to make a splash with its support.

Read more