Large Zeus Botnet Used For Financial Fraud
An anonymous reader writes "A large Zeus version 2 botnet is being used to conduct financial fraud in the UK and is operated from Eastern Europe. The botnet appears to be controlling more than 100,000 infected computers. The criminals have been harvesting all manner of potentially lucrative and revenue-producing credentials — including online account IDs plus login information to banks, credit and debit card numbers, account types plus balances, bank statements, browser cookies, client side certificates, login information for email accounts and social networks, and even FTP passwords."
login information to banks, credit and debit card numbers, account types plus balances, bank statements, browser cookies, client side certificates, login information for email accounts and social networks and even FTP passwords
I was not mad right up until that last one and even FTP passwords. They can have all that other crap but when they take my precious FTP password, and I use FTP for all my most critical-to-security interent functions, well...war on buddy.
Breaking News: Another XXl botnet steals bank account numbers. However, the acquisition of emails and Facebook accounts is worrying.
Zeus version 2
So, like a good little early adopter, I upgraded and installed version 2 on my machine only to find that it was a huge bloated piece of crap. The original Zeus was so much more simple and elegant and now this thing is just chewing up cycles. Yeah, like the customer won't notice that. Seriously, all I wanted it to do was safely back up my bank statements to a remote server in case I lose them. And after the "Zeus Certified" debacle, I don't know who to believe when I ask "Will this computer run the simplest of viruses like Adobe PDF Reader?" Clearly Zeus is just a resource hog ... and looking forward at Version 3 (if it's even released on time) one wonder if they're even trying to build a quality botnet anymore. It's times like these that make you wonder if it's time to switch over to Mariposa ...
Botnet herders have access to a very large number of computers, it was only a matter of time until they realized that the data on these computers is worth far more than the few pence they are making from Viagra spam and blackmailing gambling sites with DDOS attacks.
How do the criminals process all the information and filter out the valid ones?
Considering all these weird captchas on the login pages, I don't think it's possible to check every collected bank account automatically, and doing that manually would be too tiring.
As a precaution I've changed all my passwords to "DROP TABLE Stolen Data"
Hmm maybe we should go back to phone banking. It's not like phones can be easily hacked to sniff passwords.
Oh wait, I forgot, we aren't in the 1980s any more. Nevermind.
I think I'll do my business in person now. I'll just have to make sure the Russian Mafia doesn't set up a look-alike storefront down the street that looks like my bank's latest branch office.
Sigh.
Well, at least I know my currency is real.
Knowledge is how to play a game, intelligence is how to win, wisdom is knowing what game to play.
Mariposa is just as bloated - if not more so.
not only that, its less secure because it doesnt have a "benevolent dictator" calling the shots design-wise.
im running Conficker and its been working like a charm. granted, its market share is not that great, and as long as you hold the mouse the right way, it "just works".
honestly, i think this will be the year of the Conficker. Mariposa and Zeus are just too behind the curve.
On a side note, it would be interesting to use x'; DROP TABLE Passwords; -- as my actual password for email, banking etc, and see if A) my password is hashed for that site, and B) if it destroys their databases
Anyone doing that would be liable ten ways till Sunday. Anyone doing that to several banks would be called "A one-man super-hacker ring bent on destroying the western economic system."
Emotions! In your brain!
> Eastern Europe? What the fuck is this "Eastern Europe"? Have you ever been to the "Western Europe?" You are one fucking asshole, dweeb !!
Uh.. I'm in the UK, which is in Western Europe. This botnet is believed to be operated from the Ukraine, amongst other places, and Ukraine is in Eastern Europe. Got it now?
I do all my banking at an internet cafe
For justice, we must go to Don Corleone
Is that really large nowadays?
(-1: Post disagrees with my already-settled worldview) is not a valid mod option.
Probably. Not that it is imposible for Mac OSX and Linux to be compromised. But right now the numbers show that almost all bot net activity comes from compromised Windows PC's.
The average user wants to be able to use a computer like they use a car, or a door, or a toaster, or a toilet. No need for technical training, no cryptic messages, etc. The problem is a computer is not that kind of device. It is more like an aircraft. If you don't gain some level of technial expertise, it is easy to "crash and burn" the system.
It is a crime to put John Q Public on the internet with a Windows PC. Watching it is like watchin a baby seal be clubbed to death. They are helpless and have no clue the danger they are in.
If the government, or banks or anyone with a vested interest in the web being secure (let alone spam free) was serious. Every user would be given a liveCD of some Linux to run on their computer to browse the internet.
vi +
If you want Linux, Ubuntu, and the rest of the free OS's to stay superior and exploit-free, then why on earth would you ever want mainstream acceptance of said OS's? Wouldn't Linux et all going mainstream and replacing Windows/OSX mean that the botnets (and their owners) and scriptkiddies would then change their tactics to exploit whatever's currently dominant in market share?
If I were you, I'd be praying to the FSM for Windows/MS to stay dominant forever, just so that you could continue to use Linux without fear of someone writing script specifically to target YOUR OS's weaknesses. But that's just me
Here's to hot beer, cold women, and Glaswegian kisses for all.
Yes, but can you install WeatherBug on your Linux live CD? No? Then is isn't going to be of any use to the millions of housewives and grannies that have installed it.
Seriously, a live CD is only of use if you don't want to save anything. And no, you aren't going to get people to boot into an unfamiliar environment to do banking or whatnot.
The "other" problem is that what is really needed is an Internet Appliance for these folks. No software installs, no executable anything. It does email, web browsing, media playing and not much more. Sure, you probably want capacity to add sanctioned applications over time but it needs to operate a whole lot like an iPad - which pretty much is an Internet Appliance. This would be reasonable and could be extremely secure. More secure than the iPad is today as it has way too much capability of having stuff added to it that could be used to exploit it.
We have known about the problem for at least 10 years but nobody has done anything real about it. WebTV and a couple of other devices tried, but they were pretty restricted and oriented towards dial-up access at the time. The iPad is the first such appliance that has come along and it will be a while before it can be seen how effective it is and what the acceptance is. Clearly, we need some more wireless devices that are "appliances" that offer a limited walled garden approach and are designed with the idea of being hack-proof from the beginning.
The vast majority of (at least US) drivers certainly act like they found a driver's license at the bottom of their Cocoa Puffs box.
Faster! Faster! Faster would be better!
Given that virtually every botnet seems to originate in Eastern Europe, I can only assume that neck of the woods is now an endless tableau of McMansions, world-class prostitues, and Mercedes dealerships.
I'm sick and tired of all these Conficker fanboys. You sit and talk about your botnet being so great because its open source, and you can expose your information to any malicious actions you choose, big deal! I'll take my Mariposa walled garden any day, at least I know that I can give up my SSN, mother's maiden name, and current home address and I know it will "Just Work" when it comes to stealing my data.
Yes I did. I was not required to learn anything at all about the engine of the car. There is not even a requirement to understand the lights that say "check engine" or "oil". How many RPM's are bad for the car? What should my tire pressure be? How do I open the hood? None of those things are requirements.
Knowing how to open the door, operate the gas/break, read the stuff in the dash, that is about the same as "put a CD in" or "click on that icon there."
There is a requirement on how operate a car. Not how to buid, fix, troubleshoot, or maintain one.
vi +