Posts Tagged ‘botnet’

Zeus botnet’s C&C through Amazon EC2

Thursday, December 17th, 2009

A variant of the Zeus bot (Zbot) was found using Amazon’s Elastic Computer Cloud (EC2) infrastructure for Command&Control commands to infected machines.

Zbot is a password-stealing software, logs financial data and sends them to the botnet. Last year more than 100M US fraud was linked with Zeus malware variants. It was also held responsible for the “destruction” of 100.000 infected computers by deleting registry key data, making them inoperable. Zeus botnet is estimated to consist of millions of infected computers around the world.

(more…)

H1N1 malware epidemic

Monday, December 7th, 2009

Earlier this week, the Center for Disease Control (CDC) issued a new malware scam, to warn citizens about a large malware campaign exploiting the public awareness of phishing attacks and the interest in H1N1 vaccinations.

The E-mail security company AppRiver detected a large amount of  fake CDC e-mails which were sent at a rate of nearly 18,000 messages per minute, reaching more than 1 million in the first hour alone, according to the company’s blog post.

The e-mails claim users to register for a new state vaccination programm by creating a personal H1N1 vaccination profile at a fraudulent web page of CDC. However, anyone who clicks on the link, his computer is infected with malware, an executable copy of ZBot trojan horse. This trojan, also known as Zeus, powers one of the most active botnets which steal data of compromised machines.

According to the security company Sunbelt Software’s report,  ZBot is listed as the second most prevalent malware threat.

Malware propagation can be succesful in a situation where social engineering is dominatinated by technology due to the public awareness and fear.

Botnet hijacking

Thursday, May 7th, 2009

Security researchers at University of California, Santa Barbara have managed to infiltrate the Torpig botnet (also called Sinowal or Mebroot) allowed them to gain important new insights into one of the world’s most notorious zombie networks by collecting an astounding 70 GB worth of data stolen in just 10 days.

(more…)

First Mac botnet

Tuesday, April 28th, 2009

Researchers at Symantec found two hidden trojans – OSX.Iservice and OSX.Iservice.B – in pirated copies of Apple Computer’s iWork ’09 and Adobe Photoshop CS4 posted on some P2P networks, which use different techniques to obtain the user’s password and take control of the infected Mac machine.

(more…)