
According to Bitdefender, the Opera browser portal website (portal.opera.com) for several hours redirected users to a page with a set of Blackhole exploits.
One of the functions of BlackHole, which is most appreciated by cybercriminals, is a sophisticated traffic direction script (TDS) that supports very complex actions.
A complex malicious script was run on the portal's website, which placed on the main page an iframe element with the contents of a remote resource. Most likely, the script was uploaded using advertising posted on the portal.
According to researchers, “This malicious page contains a set of BlackHole exploits (we got an example with a PDF file that exploits the CVE-2010-0188 vulnerability), which hits an unsuccessful user with a freshly compiled ZBot”
Bitdefender employees also noted that the ZBot was downloaded from a server located in Russia, which most likely was also hacked.
Users visiting this site are advised
to check their system for malware.
A detailed report can be found
hack