Blackhole Exploit Kit Infects 2,900 Cryptome Visitors
Cryptome.org, a Website known for publishing intelligence documents and leaked files, appears to have been compromised and infected with the Blackhole exploit kit, according to documents posted on the site.
Unknown attackers breached Cryptome.org on Feb. 8 and installed the Blackhole exploit kit, Cryptome reported on Feb. 12. The infection was identified by a reader on Feb. 12. It's not clear who may have been behind the attack, but Symantec appears to be investigating the incident.
Nearly all of Cryptome's 6,000 pages in the main directory were altered to include the malicious PHP script that redirected site visitors to a third-party Website, Cryptome said. Another 5,000 files in other subdirectories were also modified. It appears that the intruders managed to change the files without modifying the time stamp on the directory.