logo

Web Attacks Target Foreign Exchange, Payment Processing Sites

ID: 0a04647d-9b67-555d-87f3-fdfa52529cc6

STIX ID: report--0a04647d-9b67-555d-87f3-fdfa52529cc6

Feed Name: Security Ledger

Threat Score
65/100

Date Published: 2012-11-29

Date Updated: 2026-05-08

Author: Paul Roberts

...
...

**Executive Summary:** Websense researchers discovered that the Cyprus-based trading site tradingforex.com was compromised to serve a malicious Java applet which exploited known Java vulnerabilities to install a Visual Basic .NET backdoor/keylogger and screen-capture tool (installer: 123.exe, signed with an expired certificate); the malicious applet also contained links to a typo‑squatting/phishing site targeting libertyreserve.com, indicating a broader criminal campaign targeting smaller financial sites.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.