Friday, July 1, 2011
Researchers discover 'indestructible' botnet
Computers infected by the software, called TDL-4, fall under control of the botnet's criminal owners and can be used to pump out spam or commit other online attacks. Communication with the botnet's command and control servers takes place over a public peer-to-peer file-sharing network and is protected by a custom encryption algorithm, making it very hard to track down the botmasters in charge and shut them down.
More than 4.5 million computers running Windows have been infected by TDL-4, but they're unlikely to know it. The malware installs itself in the computer's master boot record, a part of the system that loads before the operating system starts up, hiding it from most anti-virus programs and bypassing Window's security altogether.
What's worse, the malware runs its own anti-virus software to ensure that it doesn't have to share the infected computer with any other malicious programs. TDL-4 scans for around 20 common competitors and prevents them from contacting their command and controls servers. This also serves to stop users noticing anything is wrong - you might notice a slowdown if your computer is running a menagerie of malware, but a single botnet can remain undetected.
Tuesday, August 10, 2010
U.K. bank hit by massive fraud from ZeuS-based botnet
Security vendor M86 Security says it's discovered that a U.K.-based bank has suffered almost $900,000 (675,000 Euros) in fraudulent bank-funds transfers due to the ZeuS Trojan malware that has been targeting the institution.
The Top Ten Most wanted Spam-Spewing Botnets
Bradley Anstis, vice president of technology strategy at M86 Security, said the security firm uncovered the situation in late July while tracking how one ZeuS botnet had been specifically going after the U.K.-based bank and its customers. The botnet included a few hundred thousand PCs and even about 3,000 Apple Macs, and managed to steal funds from about 3,000 customer accounts through unauthorized transfers equivalent to roughly $892,755.
Anstis declined to name the bank. He said the botnet used in the attack is based on version 3.0 of the ZeuS malware and appears to be controlled from Eastern Europe, with a server hosted in Moldava.
From the investigation into the botnet's server operations, M86 Security has found the criminals controlling the botnet waited until accounts reached at least 800 Euros before initiating a fraudulent funds transfer from the victim's compromised machine to a number of other accounts used by money mules who would forward the funds on to Eastern Europe.
Anstis says the victimised bank was offering "free security software" to customers but it wasn't clear if this software, which M86 declined to name, was in use when the fraudulent transfers were made. Anstis says the process of notifying the bank to let it know what M86 Security has discovered about the botnet was a somewhat frustrating experience.
U.K. bank hit by massive fraud from ZeuS-based botnetThursday, March 4, 2010
Mariposa Botnet Authors and Distributors Caught
Three Spanish men were arrested last month for allegedly building an international network of more than 12 million hacked PCs that were used for everything from identity theft to spamming. According to Spanish security firm Panda Security, the massive botnet, dubbed “Marioposa” (Spanish for “butterfly”), was rented out to criminals as a delivery platform for installing malicious software such as the data-stealing ZeuS Trojan and pay-per-install toolbars.
Panda said Mariposa helped crooks steal sensitive data from more than 800,000 victims, including home users, companies, government agencies and universities in at least 190 countries.
“It is almost impossible to be sent to prison for these kinds of crimes in Spain, where prison is mainly for serious crime cases,” said Captain Cesar Lorenzana, deputy head technology crime division of the Spanish Civil Guard.
Spain is one of nearly three dozen countries that is a signatory to the Council of Europe’s cybercrime treaty, but Spanish legislators have not yet ratified the treaty by passing anti-cybercrime laws that would bring its judicial system in line with the treaty’s goals.
The Mariposa botnet takedown was orchestrated by a working group comprising Panda, the Georgia Tech Information Security Center, and Canadian security firm Defence Intelligence, which first detailed the workings of the bonnet in a white paper released in May 2009.
On Dec. 23, 2009, the working group was able to “sinkhole’ the botnet by hijacking the command and control networks that were being used to orchestrate the botnet’s activities. But according to Defense Intelligence CEO Christopher Davis, a few days later, the alleged ringleader of the Mariposa botnet gang who goes by the hacker alias “Netkairo,” bribed an employee at a Spanish domain name registrar that the gang had been using to register Web site names that helped them control the botnet.
Davis said that on Jan. 22, the hacker launched a distributed denial of service attack against Defense Intelligence’s Web site, using more than a million PCs the gang had managed to corral back into the Mariposa botnet.
Lorenzana said the three men haven’t been named publicly because they haven’t yet been charged with a crime. Until that happens, which will probably be in a couple of weeks, the men are all free on their own recognizance.
“The main problem is that even though the botnet itself has been taken down, these bots are all still infected, and these guys who operated the botnet can still go and download all the details of the data they have stolen,” Lorenzana said.
Juan Santana, CEO of Panda Security, said he hopes this case will spur Spanish lawmakers to amend the penal code to more specifically punish cyber crime activities.
“I don’t think these guys will go to jail, especially if it is the first time they have committed a crime,” Santana said. “The government needs to pass laws that are enforceable and enforced afterward.
Wednesday, December 2, 2009
YouTube Better Watch out: Koobface Botnet Exploits Social Engineering Sites
The Koobface botnet, one of the most efficient social engineering driven botnets, is entering the Xmas season with a newly introduced template spoofing a YouTube video page, in between enticing the visitor into installing a bogus Adobe Flash Player Update (New Koobface campaign spoofs Adobe’s Flash updater), which remains one of the most popular social engineering tactics used by the botnet masters.What is the Koobface gang up to? Would they continue sticking to their true nature and rely on social engineering tactics, or would they start using active exploitation tactics such as client-side exploits?
Let’s discuss some of the new developments introduced on the Koobface front over the past week, and try to answer these questions.
Experimenting with client-side exploits - last week, for the first time ever, the Koobface botnet started serving client-side exploits by embedding two iFrames on the hundreds of thousands of Koobface-infected hosts, for a period of several hours.
Despite its reliance on outdated exploits used by the web malware exploitation kit in question, this does not automatically mean that their “infection optimization” strategy would go in vain taking into consideration the fact that a huge percentage of users/enterprises continue failing to properly manage their “software inventory”.
Whether the gang would re-introduce the use of client-side exploits (drive-by download) remains yet to be seen, however, this move directly contradicts with the infection model of the botnet, which so far has been exclusively using social engineering tactics. Read More.......