Hackers Toolkit Attacks Vulnerable Browsers

SAN DIEGO, Calif. — Websense, an Online security company has issued a warning about its discovery of a do-it-yourself hackers kit being sold on a Russian website.

“The Web Attacker Toolkit,” which can be purchased for $15 to $20 exploits unpatched vulnerabilities in Internet Explorer and Firefox. The “smartbomb” virus latches onto the browsers code and then attacks its most vulnerable parts.

Websense says the hacking kit is being used on more than 1,000 websites to put a Trojan horse on susceptible computers. The worm runs in the background so surfers won’t realize their machine is being hacked. According to Websense, the Trojan can log keystrokes, download additional code, or open backdoors.

“It puts a bunch of code on a site that not only detects what browser the victim is running, but then selects one of seven different vulnerabilities to exploit,” Dan Hubbard, senior director of security and research at Websense said. “[This is] depending on how well patched the browser is.”

Interestingly, websites that host the malicious code also include a statistics page that shows “the number of infected clients, percentage of clients that have been infected, and a breakdown by country, operating system, and browser,” says Websense’s security alerts page. One of the bugs compromised 1,773 computers by using a three-year-old flaw in IE.

“Everyone knows they should patch their browsers,” Hubbard said, “but this is further evidence that that’s not happening as much as it should be.”

In its research, Websense has calculated that there have been more than 10,000 successful infections, which registers a 3 to 13 percent overall success rate.

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Brazil: New AV Requirements Set to Take Effect March 17

President Luiz Inácio Lula da Silva this week gave final approval to new regulations requiring adult websites to age-verify users located in Brazil starting March 17.

FSC Recommends Platforms Integrate StopNCII.org Tool

In a blog post, Free Speech Coalition (FSC) has recommended that platforms integrate the StopNCII.org tool to prevent the sharing of non-consensual intimate imagery (NCII).

Utah 'Porn Tax' Bill With VPN Provisions Passes State Senate

The Utah state Senate has passed a bill that would impose a 2% tax on the revenues of adult websites doing business in that state, and make sites liable if Utah minors use VPNs to circumvent geolocation.

Fast-Tracked Arizona Bill Includes Consent 'Catch-22' for Adult Sites

A bill advancing rapidly through the Arizona state legislature would impose new requirements for adult content uploaded online, including seemingly contradictory provisions that could effectively make it impossible for adult sites to operate in the state.

VirtualRealPorn Launches WebXR-Enabled Site

VirtualRealPorn has officially launched its new site, built on Web Extended Reality (WebXR) technology.

'MyAsianGFs' Launches Through Paysite.com

MyAsianGFs.com has officially launched through Paysite.com.

Corey Silverstein to Host Webinar on North Carolina Age Verification Thursday

Adult industry attorney Corey D. Silverstein has announced his latest "Legal Impact" webinar, titled "North Carolina AV Law — Content Creation Issues," to livestream Thursday at 4 p.m. (EST).

Ofcom Fines 8579 LLC $1.8 Million for AV Noncompliance

U.K. media regulator Ofcom on Monday imposed a fine of 1.35 million pounds (more than $1.8 million) against adult site operator 8579 LLC for failing to implement age checks as required for compliance with the Online Safety Act.

Pearl Industry Network Launches 'TrustLink' Creator Verification Platform

Trade group Pearl Industry Network (PiN) has launched TrustLink, its free creator verification platform.

FSC Updates Complaint in Tennessee AV Case, AG Motions to Dismiss

The Free Speech Coalition this week filed an amended complaint in its lawsuit challenging the Protect Tennessee Minors Act as unconstitutional, in response to which the Tennessee attorney general motioned for dismissal of the case.

Show More