Saturday, October 12, 2024
HomeMalwareEmployee Watched Porn at Work via 9000 Web pages Drops Malware on...

Employee Watched Porn at Work via 9000 Web pages Drops Malware on U.S Government Network

Published on

Malware protection

An Employee of  US Geological Survey (USGS) has a habit of watching pornography contents during Work hours and visiting the extensive history of porn websites which drop malware on Government Network.

U.S. Geological Survey (USGS), U.S based Earth Resources Observation and Science (EROS) Center provide science about the natural hazards that threaten lives and livelihoods; the water, energy, minerals, and other natural resources.

An IT security audit that was conducted at the U.S. Geological Survey (USGS) computer network reveals that the Employee visiting over 9000 web pages using U.S Government computers that routed via websites that originated in Russia and contained malware.

- Advertisement - SIEM as a Service

It was confirmed by the forensic report he/she saved many of the pornography images were saved in unauthorized personal USB and Android devices.

Officials said, “During the investigation, we identified two vulnerabilities in the USGS’ IT security posture: website access and open USB ports. Malware is rogue software that is intended to damage or disable computers and computer systems.”

The main motivation of the malware that dropped from the Russian based website is intended to steal the sensitive information from the government network.

According to the report that issued by  U.S. Department of the Interior’ s (DOI’s) IT Rules of Behavior prohibit employees from using DOI systems for illegal or inappropriate activities, explicitly including the viewing or distribution of pornography..

Also, they didn’t reveal the details about the Malware and the employee details who was involved in this activities.

USGS Recommendation for Better security 

USGS recommended to follow strong blacklist policy of known rogue URL or domains and regularly monitor employee web usage history.

Direct employees to refrain from connecting personal devices, such as USB drives and cell phones, to Government-issued computers or networks.

“EROS Center has deployed enhanced intrusion detection systems and firewall technology to assist in the prevention and detection of rogue websites trying to communicate with Government systems”

We further recommend that USGS employ an IT security policy that would prevent unauthorized USB devices on all employee computers.

Best practices for malware incident protection include restricting the use of removable media and personally owned mobile devices.

Also Read:

Beware! Downloader Malware Disguised as Game Apps Found On Google Play with More Than 51,100 Installations

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Threat Actor ProKYC Selling Tools To Bypass Two-Factor Authentication

Threat actors are leveraging a newly discovered deepfake tool, ProKYC, to bypass two-factor authentication...

Mozilla Warns Of Firefox Zero-Day Actively Exploited In Cyber Attacks

A critical use-after-free vulnerability affecting Firefox and Firefox Extended Support Release (ESR) is being...

SpyCloud Embeds Identity Analytics in Cybercrime Investigations Solution to Accelerate Insider and Supply Chain Risk Analysis & Threat Actor Attribution

IDLink, SpyCloud’s new automated digital identity correlation capability, is now core to its industry-leading...

Abusix and Red Sift Form New Partnership, Leveraging Automation to Mitigate Cyber Attacks

The agreement has marked over 600,000 fraudulent domains for takedown in just two months...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

LemonDuck Malware Exploiting SMB Vulnerabilities To Attack Windwos Servers

The attackers exploited the EternalBlue vulnerability to gain initial access to the observatory farm,...

DCRAt Attacking Users Via HTML Smuggling To Steal Login Credentials

In a new campaign that is aimed at users who speak Russian, the modular...

LummaC2 Stealer Leverages Customized Control Flow Indirection For Execution

The LummaC2 obfuscator employs a novel control flow protection scheme designed specifically for its...