Computer Help Community

Community

Cyber Tech Help Community

New Tutorials

PC Tutorials

New Downloads

More Downloads
PC Downloads

Member Testimonials

Open Member Quote   I just wanted to say thanks to all the members, staff and admins/owners for all the help they have given me with all my problems. I see how huge this site is, and how active it is, and it amazes me how well run it is, and what great staff you guys got here - __James__  Close Member Quote
Member Testimonials
MY CYBER TECH HELP

LATEST TOPICS

Tech Help Community

Free Antivirus Scan

Free Virus Scan and a listing of the top 10 viruses in the wild - Free Antivirus Scan
Free Online Antivirus Scan

File Extension Database

Find what program a filetype belongs to in our searchable File Extension Database.
File Extension Database

Related Microsoft Links

Services
Cyber Tech Help Community

To the top of the page to top

 



Computing News | Botnet that pwned 100,000 UK PCs taken out

Latest News Latest News | News ArchiveNews Archive | Cyber Tech Help News RSS Feed!

Posted by: Degsy
Date added: 06:40 Thursday, 5th August 2010 GMT
Source: The Register

Security researchers have uncovered the command and control network of a Zeus 2 botnet sub-system targeted at UK surfers that controlled an estimated 100,000 computers.

Cybercrooks based in eastern Europe used a variant of the Zeus 2 cybercrime toolkit to harvest personal data - including bank log-ins, credit and debit card numbers, bank statements, browser cookies, client side certificates, and log-in information for email accounts and social networks - from compromised Windows systems.

Trusteer researchers identified the botnet's drop servers and command and control centre before using reverse engineering to gain access its back-end database and user interface. A log of IP addresses used to access the system, presumably by the cybercrooks that controlled it, was passed by Trusteer onto the Metropolitan Police.

Trusteer declined to point the finger as to the locations of the Zeus botmaster controlling the systems, beyond saying that compromised systems were controlled from eastern Europe.

"The cybercrime servers were hidden but the hackers were not using a lot of security, so it was possible to find a way into the database," Mickey Boodaei, Trusteer's chief exec told El Reg.

The original attack was probably seeded by a combination of infected email attachments and drive-by downloads, according to Amit Klein, Trusteer's chief technology officer. The Windows-based malware used to control zombie clients was a variant of the infamous Zeus cybercrime toolkit, a customisable Trojan keylogger and botnet-control client sold through underground forums that's become the sawn-off shotgun of the cybercrime economy over recent years.

"There are some significant changes between Zeus 1.x and Zeus 2.0: Zeus 2.0 installs differently, better adapted to newer Windows operating systems (Vista, 7). Additionally, Zeus 2.0 has built-in support for Firefox," Klein explained.

"There are Zeus binaries out there for few months already with version number 2.0.x.y. We do not control Zeus's version numbers - it's the Zeus writers who do that," he added.

Trusteer says the attack is an example of the growing trend of regionalised malware.

Tools:  Tools: Post a comment | Link to this news item | Send to a friend | Submit News

 

Post a commentPost a comment

Error: You are not logged in.

In order to leave comments to news articles you must be a Cyber Tech Help Member.

Registration is completely free!  Register to become a member!  Register to become a member

Along with access to leave comments to news articles you will be able to ask any computing questions you might have on the Cyber Tech Help Forums.

 

[ To the top of the page To top | Latest News Latest News | News Archive News Archive | Cyber Tech Help News RSS Feed! ]