Information Age: News, analysis & insight for IT & business leaders

Giant botnet infiltrates 2,500 organisations

19 February 2010  

A network of 74,000 compromised PCs found stealing passwords, data and entire identities, according to a US security company

A botnet consisting of over 74,000 malware-infected PCs has accumulated a gigantic cache of stolen data, taken from over 2,500 businesses and government organisations across the world, a US security vendor claimed yesterday.

NetWitness found that the botnet, which it has dubbed ‘Kneber’, has over the past 18 months accumulated “68,000 corporate login credentials, access to email systems, online banking sites, Facebook, Yahoo, Hotmail and other social networking credentials, 2,000 SSL certificate files, and dossier-level data sets on individuals including complete dumps of entire identities from victim machines”, according to a company statement.

A Wall Street Journal report said that the affected companies included Paramount Pictures and Juniper Networks, as well as 10 US government agencies.

NetWitness said that the botnet is based on a notorious – and freely available – piece of malware called ZeuS. "Many security analysts tend to classify ZeuS solely as a Trojan that steals banking information, but that viewpoint is naïve," said Alex Cox, a principal analyst at the company. Based on NetWitness’ analysis, he said, it is clear that the ZeuS has a more diverse set of objectives, and targets many more kinds of information than previously thought.

The company said that there is some evidence linking the botnet to criminal gangs in Eastern Europe, and that computers based in China may have been involved.


Comments  [1]

Rossano Ferraris
Tuesday 23rd February 2010

This is a variant of the well known Zeus bot otherwise known as Zbot. Once executed on the target machine –which becomes an infected bot- it downloads a configuration file from the C&C server (Command & Control server) which instructs the bot to capture desired data.
It creates a hidden folder on the infected machine and it drops a modified copy of itself to avoid security scanner detection.
The bot periodically uploads the captured data to the server and schedules an update of the configuration files permitting the criminal hacker to change the instructions of the bot.
Additionally it disables the firewall on the target machine.

Rossano Ferraris, CA ISBU Research Team

Report this comment »

People who read this also read...

Microsoft secures court order to disarm botnet

Software giant wins court case allowing it to decapitate global network of malware-infected PCs

Inside the swarm

How the deadly combination of SQL injections and botnets is fuelling an industrial revolution in cybercrime

Twitter phishing may be designed to exploit search engines

A recent spate of phishing attacks on the popular microblogging service may be an attempt to influence search engine results, says security vendor

Profits down for Dell, despite revenue growth

Computer maker's latest financial results baffle analysts, as net income falls on healthy revenue rise

Three arrested in connection to ‘world’s largest botnet’

Spanish police have arrested three men after volunteer working group disabled the Mariposa malware network

 

White Papers

Read article

'Think Lean' When Developing Management System Documentation

Learn how to efficiently and effectively implement a document management system for your organization.

Read article

11 Hiring Trends for 2011

In this document, you'll get the insider info you need to give potential employers what they want and beat your competition in 2011. You'll learn about the most valuable certifications and the game-changing skills that can lead to more job security and stability.

Read article

12 Hiring Manager Secrets to Getting the IT Job You Want

Learn how you can make yourself a more attractive candidate now with PrepLogic's free 12 Hiring Manager Secrets to Getting the Job You Want.

More
Advertisement
div class="banner">