Adobe Flash Language Used to Hide Malicious Code
New research has found attackers are abusing Adobe System's ActionScript programming language to dodge anti-malware defenses.
ActionScript is the programming language of the Adobe Flash platform. In a recap of the threat landscape for the first six months of 2010, M86 Security reported observing attackers combining JavaScript with ActionScript in a bid to obfuscate malicious code.
“Due to the widespread adoption of Adobe Flash across the Web, Flash continues to remain a popular choice for developers, particularly in the realm of Web development,” the researchers wrote. “What is less known is that ActionScript has a handy interface with JavaScript on the parent page. This little known fact is exactly the feature being abused by attackers today.” Using the predefined functionality in ActionScript for “ExternalInterface,” attackers can produce a two-way communication between Flash and JavaScript, the report explains.