Showing posts with label botnet. Show all posts
Showing posts with label botnet. Show all posts

Friday, April 16, 2010

Zeus Botnet Exploits PDF "Feature"


"The Zeus botnet is now using an unpatched flaw in Adobe's PDF document format to infect users with malicious code, security researchers said today.

"The attacks come less than a week after other experts predicted that hackers would soon exploit the `/Launch` design flaw in PDF documents to install malware on unsuspecting users' computers.

"The just-spotted Zeus variant uses a malicious PDF file that embeds the attack code in the document, said Dan Hubbard, CTO of San Diego, Calif.-based security company Websense. When users open the rogue PDF, they're asked to save a PDF file called `Royal_Mail_Delivery_Notice.pdf.` That file, however, is actually a Windows executable that when it runs, hijacks the PC.

"Zeus is the first major botnet to exploit a PDF's /Launch feature, which is, strictly speaking, not a security vulnerability but actually a by-design function of Adobe's specification. Earlier this month, Belgium researcher Didier Stevens demonstrated how a multistage attack using /Launch could successfully exploit a fully-patched copy of Adobe Reader or Acrobat..."


From ComputerWorld...

Monday, February 22, 2010

Chuck Norris Wants Your Router


"If you haven't changed the default password on your home router, you may be in for an unwanted visit from Chuck Norris -- the Chuck Norris botnet, that is.

"Discovered by Czech researchers, the botnet has been spreading by taking advantage of poorly configured routers and DSL modems, according to Jan Vykopal, the head of the network security department with Masaryk University's Institute of Computer Science in Brno, Czech Republic.

"The malware got the Chuck Norris moniker from a programmer's Italian comment in its source code: `in nome di Chuck Norris,` which means `in the name of Chuck Norris.` Norris is a U.S. actor best known for his martial arts films such as `The Way of the Dragon` and `Missing in Action.`

"Security experts say that various types of botnets have infected millions of computers worldwide to date, but Chuck Norris is unusual in that it infects DSL modems and routers rather than PCs."


From PC World...

Tuesday, October 20, 2009

Bank Botnet Bonanza


"The massive Zbot botnet that spreads the treacherous Zeus banking Trojan has been launching a wave of relatively convincing phishing attacks during the past few days -- the most recent of which is a phony warning of a mass Conficker infection from Microsoft that comes with a free "cleanup tool."

"The wave of attacks began early last week targeting corporations in the form of email messages that alerted victims of a `system upgrade.` Email is accompanied by poisoned attachments and links; in some cases it poses as a message from victims' IT departments, including their actual email domains, and alerts them about a "security upgrade" to their email accounts. The message then refers victims to a link to reset their mailbox accounts, and the link takes them to a site that looks a lot like an Outlook Web Access (OWA) page, but instead infects them with the Zeus Trojan.

"Today, researchers at F-Secure spotted the botnet spamming out malware-laden email that tries to trick recipients with a convincing lure messages that says, `On October 22, 2009 server upgrade will take place.`

"`What we're seeing is an evolving campaign of different lures to see which one works,` says Richard Wang, manager of Sophos Labs in the U.S.

"The Zbot botnet, which is made up of 3.6 million PCs in the U.S., or 1 percent of all PCs in the country, according to data from Damballa, spreads the deadly Zeus Trojan. Zeus, which steals users' online financial credentials, represents 44 percent of all financial malware infections today, according to Trusteer."


From DarkReading...

Wednesday, April 22, 2009

I Like Big Bots And I Cannot Lie


Baby Got Haxx

"The world's largest-ever malware network has been uncovered, affecting 1.9 million corporate, government and consumer computers.

"Finjan Inc's Malicious Code Research Center (MCRC) uncovered the network as part of research into command and control servers operated by cybercriminals.

"`It is the biggest ever - 600,000 was the largest last year,` a spokesman for Finjan told TG Daily. He declined to name the organisations affected, but said `I think you can assume that most large corporations and most western governments are affected.`"


More at TG Daily...

Friday, April 17, 2009

Evidence Of Zombie Mac Botnet Found


"If you let yourself get tempted into installing the pirated versions of iWork or Photoshop CS4 that circulated on Bit Torrent earlier this year, you may have unwittingly turned your Mac into a zombie. Security researchers for Symantec have turned up evidence that these zombie machines are being used to create a Mac-based botnet.

"Botnets are used to perform DDoS attacks on systems, gather sensitive personal information, and send out a majority of the spam that clogs up the 'Net. While commonly made out of infected Windows computers, this is the first known attempt to create one from Macs..."


More at Ars Technica...

Wednesday, March 4, 2009

No Honor Among Cyberthieves


"Cyber-crooks are not only exploiting security flaws in popular software in order to steal from vulnerable and innocent users. Independent Security Consultant Dancho Danchev describes how vulnerabilities in unpatched releases of the Zeus crimeware kit are being exploited by hackers in order to steal resources from their fellow criminals.

"The security researcher has come across an interesting posting made by a botnet runner, who asks for help to secure his infrastructure after being compromised several times by other hackers. According to his own account, someone hijacked his botnet, composed of over 100,000 compromised computers, by exploiting a vulnerability in the Zeus kit, which allowed remotely injecting a high-level account into the administration panel of the crimeware..."


Read the full article at Softpedia...

Friday, February 27, 2009

Time Warner DNS Servers Hammered


"During the past week, hackers have launched a series of attacks on Time Warner Cable's servers. Time Warner Cable is working with law enforcement agencies to resolve these crimes.

"As a result of these attacks, you may have experienced a temporary `outage` when attempting to surf the Web, including an intermittent `page cannot be displayed` error message. The outages did not result in services being 100% unavailable; and were limited to sporadic timeouts which appeared to be random events. Some users may have experienced a total disconnect, however. These types of attacks are not uncommon, especially for a network as large as ours. We suspect that the attackers are using `zombie computers,` or hijacking unsuspecting subscribers' machines to perpetrate the attack without its owner's knowledge.

"All of us at TWC take these attacks extremely seriously. As previously mentioned, we are working with the appropriate law enforcement agencies that specialize in investigating these types of crimes. We will pursue prosecution of all perpetrators to the fullest extent of the law. We apologize for the inconvenience that these attacks may have caused and encourage you to report any suspicious activity."


From help.rr.com...

Friday, December 26, 2008

FBI On Hacker Hunt Road Trip


"America's crime hunters, the FBI, are on a worldwide computer-crime chase that has brought them to New Zealand.

"They are looking for a hacker who has headed up a global group using other people's computers as a vehicle for cyber crime.

"Since June last year, the group is thought to have attacked more than a million computers, ripping off victims to the tune of nearly $20 million...

"The FBI probe has seen a series of arrests around the world...

"Authorities in New Zealand, working in collaboration with the FBI Philadelphia office, conducted a search this week at the residence of an individual who goes by the cyber ID of akill.

"Akill is believed to be the ringleader of an elite international botnet coding group that is being blamed for infecting more than a million computers, making money for organised crime."


From TVNZ...

Tuesday, December 9, 2008

Penis pill botnet awakens after McColo shutdown


"One of the three botnets cut off by the shutdown of rogue ISP McColo is back in business. The Mega-D botnet is back on its feet and throwing off huge volumes of spam, net security firm Marshal8e6 reports.

"The botnet - best known for spamvertising adverts for penis pills - has been linked back to a network of compromised zombie PCs through a new command and control infrastructure. Analysis of where these systems are located is ongoing and neither Marshal8e6 or its competitors are prepared to point the finger of blame just yet. What's not in any doubt is that junk mail from compromised systems is on the rise."


More at The Register...