Slashdot Mirror


Cybercriminals Shifting To Bugat

wiredmikey writes "Cybercriminals are changing up their weapons, trying to diversify their attack tools using a platform that is less well known and therefore harder to detect and block. With so much focus on the ZeuS Trojan, recent attacks utilized a variant of 'Bugat,' another Trojan horse that steals information from a compromised computer and sends it to a remote host. Bugat was first discovered in January of this year but, like ZeuS, has seen some different variants. In last week's attack, LinkedIn users received emails alerting them of a 'Contact Request,' and encouraging them to click through to a malicious URL where a java applet fetched and installed the Bugat executable."

13 of 48 comments (clear)

  1. Make Up Your Mind by WrongSizeGlass · · Score: 2, Informative

    In the linked article they claim "Bugat" was being distributed via the recent attack targeting LinkedIn users but the article they use as their reference clearly states the LinkedIn spam was distributing "ZeuS". Make up your mind, M'kay?

    1. Re:Make Up Your Mind by cerberusss · · Score: 3, Informative

      The reference article has been updated:

      Update - 10/12/10 9:50AM - There have been reports that this attack used "Bugat" Malware instead of Zeus (More)

      --
      8 of 13 people found this answer helpful. Did you?
  2. Finally! by digitaldc · · Score: 2, Funny

    After years of inactivity and wondering exactly what is its purpose, I have now discovered a reason to having a profile on LinkedIn.
    Meeting new people, discovering professional contacts and getting viruses!

    --
    He who knows best knows how little he knows. - Thomas Jefferson
  3. I'd avoid clicking them on pages, too by Jeremiah+Cornelius · · Score: 4, Funny

    Let's start with email and forums, yes.

    But the question is open: What are these "hyperlinks" really for, anyway? The dubious benefits delivered at the other end of clicking is seldom worth the exhilaration. I say that we should just eliminate them, altogether!

    I envision a large screen - you could make it large enough to occupy a central place in the household. This could be used to deliver appropriate, scheduled media and information: remote through a wireless, one-to-many transport or stored locally on different removable media.

    I think there are significant opportunities to greatly simplify the user interface of such a device, and we will eliminate the risks associated in hyperlinking.

    --
    "Flyin' in just a sweet place,
    Never been known to fail..."
    1. Re:I'd avoid clicking them on pages, too by Jesus_666 · · Score: 2, Funny

      Your idea is intriguing but with the lack of accountability as to who is consuming what when, the content industry would never allow the distribution of movies and shows over your new network. Without multimedia capabilities, who would use it?

      --
      USE HOT GRITS WITH STATUE OF NATALIE PORTMAN (NAKED AND PETRIFIED)
  4. I just love press releases by tsu+doh+nimh · · Score: 3, Informative

    Wondering how much this "story" actually differs from the Trusteer press release, below: NEWS RELEASE FOR IMMEDIATE DISTRIBUTION
    Trusteer Researchers Find Criminals are Diversifying Financial Attacks with New Version of Bugat Malware

    Bugat Quietly Distributed in Recent LinkedIn Phishing Assault; Unlike Zeus Trojan, it is Less Well Known and Harder to Detect

    NEW YORK, Oct. 12, 2010 -Trusteer, the leading provider of secure browsing services, today announced that its researchers have discovered a new version of the Bugat financial malware used to commit online fraud. Bugat was distributed in the recent phishing campaign targeting LinkedIn users, which was generally considered to be trying to infect machines with the more common Zeus Trojan. The emergence of this new version of Bugat appears to be an attempt by criminals to diversify their attack tools using a platform that is less well known and therefore harder to detect and block.

    Bugat is similar in functionality to its better known financial malware brethren Zeus, Clampi and Gozi. It targets Internet Explorer and Firefox browsers and harvests information during online banking sessions. The stolen financial credentials are used to commit fraudulent Automated Clearing House

    (ACH) and wire transfer transactions mostly against small to midsized businesses, which result in high-value losses. Bugat is three times more common in the US than Europe, but its distribution is still fairly low.

    In last week's attack, LinkedIn users received emails reminding them of pending messages in their account and providing a malicious URL. When a victim clicked on the link they were directed to a fraudulent website where a java applet fetched and installed the Bugat executable. LinkedIn spam email is an effective tool to push malware to enterprise users, and is being used to gather credentials for commercial bank accounts and other sensitive services used by businesses.

    "Criminals are stepping up their malware distribution efforts by continuously updating configurations of well known malware like Zeus, and using new versions of less common Trojans like Bugat, to avoid detection,"

    said Mickey Boodaei, CEO of Trusteer. "We are in an arms race with criminals. Although Zeus gets a lot of attention from law enforcement, banks and the security industry, we need to be vigilant against new forms of financial malware like Bugat and SpyEye which are just as deadly and quietly expanding their footprint across the internet."

    Trusteer warns that the recent industry focus on Zeus is making it easier for other Trojans, like Bugat, SpyEye, and Carberp which are less wide spread but equally sophisticated, to avoid detection. Carberp currently targets nine banks in the United States, Denmark, The Netherlands, Germany, and Israel. These lesser known financial malware platforms are expected to increasingly compete with the Zeus toolkit to become the new Trojan of choice for criminal groups.

    Blocking and Removing Bugat

    The Trusteer Secure Browsing Service protects banking and other online sessions by blocking attacks and then disinfecting machines that are infected with Bugat and other financial malware including Zeus, SpyEye, and Carberp. When a Trusteer user browses to sensitive websites such as internet banking, Webmail, or online payment pages, the service immediately locks down the browser and creates a tunnel for safe communication with the web site. This prevents malware like Bugat from injecting data and stealing information entered and presented in the browser. The service is directly connected to the bank (or other online business protected by Trusteer) and to Trusteer's 24x7 fraud analysis service. Attempts to steal money from consumers protected by Trusteer are immediately detected by the bank or operator of the website and are blocked using various layers of protection.

    --
    ...because you never know who you're dealing with.
  5. Re:Moral of the story: never click through by mspohr · · Score: 2, Interesting
    Not "clicking through" is not a realistic option.

    I switched to Linux (and my wife and daughters to Macs) a few years ago and I don't worry about malware any more. (Note to partisans: I know that both of these OSs can be "theoretically" compromised but the reality is that it just doesn't happen since you need to be a really stupid user and type in your password to give the malware access to do any real damage.)

    I've set up VMs for Windows if I absolutely must run some Windows software but I've found I rarely use them.

    - It did cost some time and money to switch but...

    - Freedom from malware... priceless.

    --
    I don't read your sig. Why are you reading mine?
  6. According to Symantec, Windows only by david.emery · · Score: 2, Interesting

    But of course, I had to dig to find that particular piece of information. Most of the write-ups ignore the question of what host OS/systems are vulnerable. http://securityresponse.symantec.com/security_response/writeup.jsp?docid=2010-013112-4647-99

    It's truly appalling that the great number of discussions are either (a) ignorant of the question of 'host vulnerability', (b) assume that everyone is running Windows; or (c) can't be bothered to determine what hosts are vulnerable. If I were sufficiently paranoid, I'd believe this is part of the continuing conspiracy to make everyone believe that such vulnerabilities are a 'fact of life' for all computers, and not just Microsoft products.

  7. Re:This is embarassing by e70838 · · Score: 2, Funny

    I was not able to download bugat from this link. Do you have another one ?

  8. Running Mac OS... by Chris+Tucker · · Score: 2, Informative

    ...in a user account when online, NEVER as Root, and Little Snitch is ALWAYS running in the background in ALL accounts, especially Root.

    Ad Block Plus is also running at all times, that helps to eliminate the threat posed by hijacked banner or other ads.

    Yes, the potential for the Mac to be compromised is there, but I'd have to do something really stupid to get malicious code onto the machine.

    (Insert your own gratuitous but not unwarranted slams against the Windows OS here.)

    --
    Guaranteed! This comment 100% Anthrax free!
    1. Re:Running Mac OS... by Beerdood · · Score: 2, Funny

      I'm running Linux, so I don't care.

      Bwahahahah!

      Dear Malware coders :

      Please work on creating more linux based malware and viruses. There simply isn't enough Linux Malware out there - I believe the parent post clearly shows that there are plenty of smug linux users out there that believe their computers are impenetrable fortresses.

      You see, it's a win-win situation for you regardless of what happens. Either
      a) Linux becomes the dominant operating system, jumping from 0.1% to 95% of the market share. In this scenario, your malware reaches a significantly higher number of unsuspecting users.
      b) Linux becomes even more obscure and Windows based operating systems are still the dominant choice of operating system. In this scenario, your existing Windows malware will continue to prevail and infect more and more users switching over from Linux to Windows.

      Please carefully consider my proposal. I'm sure you'll find that we can agree that there needs to be a lot more Linux based Malware out there, so get coding. Also, I would gladly send $60 for your "free anti-virus software" just imagining the look on the faces of pretentious linux users when they find their system is infected.

      Sincerely,
      Beerdood

      --
      Global warming and other natural disasters are a direct effect of the shrinking number of pirates - Gospel of the FSM
  9. Simple solution by Todd+Knarr · · Score: 5, Insightful

    When is the simple solution going to be applied by users: never trust links in e-mail. If I got an e-mail from LinkedIn telling me about a contact request, I'd ignore any URL in the e-mail. I'd go to LinkedIn itself through the bookmark already in my browser. If it's a real contact request, it'll be sitting in my inbox there waiting for me. I don't need to trust anything in the e-mail. And if there isn't anything waiting in my inbox, then the e-mail was a fake and I shouldn't be trusting anything in it.

    It's the same rule as for unsolicited phone calls. If someone calls you up claiming to be from the power company saying you've got an overdue balance and you have to pay up or have power shut off, you do not accept their helpful offer of doing the payment over the phone if you'll just give them your bank-account number to do an e-check. You've no idea whether it's actually the power company calling or just some random con-man. You thank them, hang up, pull out your last bill and get the customer-service number from that. Then you call that number and ask them about the status of your account. And if they say you are, it's now safe enough to do an e-check because (barring someone having usurped the phone company's switches themselves, or having switched physical bills on you) you know you're really talking to the power company.

  10. /. now a Microsoft PR drone? by lowlands · · Score: 2

    It's nice to see that even /. will not clearly specify that this is a Microsoft Windows-only problem. The Microsoft PR drones have been "generalizing" and "de-Windowfying" the trojan/virus/malware problem for a while now. And quite successful it seems when even /. serves its articles the way Microsoft's PR drones like to see them. If you read the first sentence then it is basically unclear, to the untrained, inexperienced eyes of this world, that this is not a problem for all Operating Systems and platforms but unique to one particular vendor. Time to give the Microsoft PR drones more work and put the blame were it belongs.