Chalk up one for the defenders. Here’s how a trio of security researchers used a three-step attack to defeat a 250,000-pronged botnet.
Showing posts with label Botnet. Show all posts
Showing posts with label Botnet. Show all posts
Tuesday, December 29, 2009
Good Guys Bring Down the Mega-D Botnet
Chalk up one for the defenders. Here’s how a trio of security researchers used a three-step attack to defeat a 250,000-pronged botnet.
Thursday, October 29, 2009
Facebook Password reset scam is Bredolab botnet attack
Virus hunters are raising the alarm for a large-scale spam attack that uses fake Facebook password-reset messages to trick PC users into downloading a dangerous piece of malware.The malicious executable is linked to the Bredolab botnet, which has been linked to massive spam runs and identity-theft related attacks.
According to Websense, the address of the sender is spoofed to display “support@facebook.com,” a trick commonly used to trick targets into believing it’s a legitimate e-mail from the popular social network.
The messages contain a .zip file attachment with an .exe file that connects to two servers to download additional malicious files and joins the Bredolab botnet which means the attackers have full control of the PC, such as steal customer information, send spam emails. One of the servers is in the Netherlands and the other one in Kazakhstan.
Thursday, July 30, 2009
Severe Threat: Clampi Trojan revealed as financial-plundering botnet monster
A close look at the Clampi Trojan, an elusive piece of malware that uses encryption to help hide its nefarious data-stealing deeds, reveals it to be a botnet-controlled monster that can swipe a victim's sensitive data associated with more than 4,500 different sites, according to one researcher."We've been able to get through the layers of encryption in Clampi," says Joe Stewart, director of malware research at SecureWorks. "Clampi is collecting data associated with about 4,600 key sites, such as banks and other financial institutions targeted by criminal networks."
But it doesn't stop there.
Clampi is going after utilities, market research firms, online casinos and career sites, in a broad sweep to grab personally identifiable information, such as credentials and account information, that might be of use to criminals for financial gain. Clampi, also known as Ligats, Ilomo or Rscan, is using psexec tools to spread across Microsoft-based networks in a worm-like fashion.
SecureWorks
So far, the analysis by SecureWorks has identified 1,400 specific sites in 70 countries out of the 4,600 or so total sites the Clampi Trojan appears programmed to monitor once it has infected a victim's Windows-based machine.
The design
The design of the Clampi Trojan, which was first spotted in 2007, reveals its creator has gone out and methodically figured out a lot about the target sites.
He says the 4,600 number is enormous in comparison to what is usually found in Trojans designed for stealing financial data from victims trying to conduct transactions at online Web sites. Most Trojans of this sort, such as Zeus, normally would have not more than 30 banks as a target.
A Worm
The Clampi Trojan, once it worms its way into a victim's machine, will watch for the victim to try and do anything online associated with any of the 4,600 different sites and then leap into action to steal data, transferring it via an encrypted channel back to command-and-control servers.
According to SecureWorks, Clampi's main way of spreading is through drive-by downloads when a user visits a Web site that has been compromised by attackers.
Trusted Sites
Some of these sites may be trusted as legitimate by Web visitors, but the site has been compromised, often because the Webmaster or network manager security credentials for it have been stolen and the attacker has simply loaded up the malware to enable the Clampi drive-by download.
The Clampi Trojan, believed to have infected hundreds of thousands of machines, basically functions as a botnet under the command-and-control of a botmaster, probably in Eastern Europe or China.
Botnet
As a botnet, it is sweeping up victim's sensitive personal data and sending it back through a set of command-and-control servers to cybercriminals. Clampi seems to be picking up speed in its spread since July and may be the Trojan used in a cybertheft scam that hit the US earlier this month.
Command and Control
The Clampi command-and-control server is encrypted by 448-bit blowfish encryption, using a randomly generated key that is sent to the control server using 2,048-bit RSA encryption. SecureWorks got through the encryption layer by intercepting the session key in a test system and decrypting the network traffic. This allowed the security firm to examine the list of Web sites targeted by a module that's part of Clampi.
How can you defend yourself against Clampi?
There is no product you can buy to stop this as a zero-day attack, although antivirus software might eventually detect it and stop it later on your machine.
The best recommendation, is to find a way to use a "separate system" to conduct financial transactions, one that is not the same system as you might use to browse the Internet. That would lower the risk of being infected by the Clampi Trojan.
Labels:
Botnet,
encryption,
hacking threats,
trojans,
vulnerability
Subscribe to:
Posts (Atom)