What is Web-based Malware?
Web-based Malware is an emerging security threat for websites and web users. Hackers are now planting malicious code on legitimate websites in an effort to distribute viruses to consumers. (This attack is often called a “drive-bydownload”). Once the viruses are installed on users’ PCs, the hackers can monetize those compromised PCs in various ways (including logging users’ keystrokes or using the compromised PCs to send spam email).
The malicious code that hackers inject on websites is Web-based Malware, and it is very different from the typical virus that might infect a user’s PC. Web-based Malware runs in a web browser and often works by embedding in, sourcing in, or redirecting to malicious content from a hacker's website. Web-based Malware can be written in HTML, Javascript, Dynamic HTML, AJAX, Flash, PDF, or a variety of other programming languages. By contrast, a PC-based virus often takes the form of an executable file that runs code directly on the computer's microprocessor as opposed to being interpreted by the web browser. Attackers often use Web-based Malware to infect web pages so that those web pages can serve as distribution points for traditional, PC-based viruses.