WHID 2008-05: Drive-by Pharming in the Wild

Attack Information
WHID ID: 
2008-05
Date Occured: 
28 Jan 2008
Attack Method: 
Attack Method: 
Outcome Information
Outcome: 
Target Information
Attacked Entity Field: 
Finance
Attacked Entity Geography: 
Mexico
Attacked System's Technology: 
DSL Router

Symantec reported an active exploit of CSRF against residential ADSL routers in Mexico (WHID 2008-05). An e-mail with a malicious IMG tag was sent to victims. By accessing the image in the mail, the user initiated a router command to changethe DNS entry of a leading Mexican bank, making any subsequent access by a user to the bank go through the attacker's server.

Additional information: