Secure Channel - Malware, Worms, Viruses - Clampi Trojan Renews Assault on Bank Accounts
Sporadic reports are surfacing that the authentication credential stealing Trojan Clampi is regaining momentum and poised to begin a new round of stealthily siphoning cash from the bank accounts belonging to compromised users.
Clampi - also known as Ligats, Ilomo and Rscan - was first discovered in January 2008. The Trojan targets machines running nearly all versions of Windows and spreads as a drive-by download through Websites with compromised vulnerabilities in Flash and ActiveX. It sits in the background monitoring Web browsing activity, specifically log-ins to accounts with financial activity. Without impeding connections or PC performance, Clampi stealthily captures users' account IDs and authentication credentials and passes them to its master.
In recent months, Clampi has started spreading like a worm across networks with infected PCs. In a CNET report, SecureWorks' Joe Stewart explained that Clampi uses capture domain registration credentials to leverage the Windows SysInternals tool "psexec" to copy itself across all connected computers within a domain.
What makes Clampi different, according to published reports, is that it's monitoring a vast number of financially sensitive accounts. Banks and financial institutions are its prime target, but it's also monitoring retail sites, utilities, ad networks, government agencies, online casinos and military portals.
The threat is not contained to individual home users. The Washington Post previously reported Clampi is responsible for several large, unauthorized bank transfers. A Kentucky county lost more than $415,000 to cyber-criminals after a treasurer's PC was compromised. A Pennsylvania school district was hit to the tune of $700,000 and an auto parts store in Georgia lost $75,000, the newspaper reported.
The conventional advice for dealing with Clampi is much the same as with all malware in the wild: Update antivirus signatures, monitor inbound and outbound traffic, block traffic from suspicious or known malicious domains, and patch vulnerability applications and services. In his interview with CNET, Stewart went a step further to say that businesses should isolate PCs used for high-value activities such as managing financial transactions and that those same machines should never be used for browsing the Web or accessing e-mail.
Shared via AddThis
Showing posts with label worms. Show all posts
Showing posts with label worms. Show all posts
Friday, September 25, 2009
Tuesday, August 4, 2009
Nine very scarey things about Botnets
In a shrinking universe, the Botnet world is expanding.Let me warn you that this article will paint a scarey picture of botnets taking over all PCs, both the ones on corporate networks as well as the ones at home.
I am sure you have long wondered just how widespread the botnet problem is. What you will learn is enough to make you want to return to the days of stand-alone computing. The reality is worse than most people suspect.
Here is a list of nine known things about botnets that will scare you but perhaps this article will help you to increase your effort to keep your PCs off the illicit botnets.
1. The process of developing software that creates and controls botnets has reached a professional level. Forget the amateur script kiddies that are out for kicks; developers are in it to make a lot of money. The techniques they use to create malware or command and control software are as sophisticated as those used by any commercial software company.
What's more, this underground development community is very cooperative, like a quasi-legitimate open source community. Software is shrink-wrapped, packaged and sold or passed around. The developers add their "personal touches" to create many variants of the malware. Finjan reports that the Golden Cash network operated by cybercriminals provides an exploit toolkit as well as an attack toolkit to distribute malware.
2. Once a PC is captured by a botnet, the use of that PC can be bought and sold many times e.g. the Golden Cash network is a vast botnet exchange. Cyberthieves purchase malware-infected PCs from anyone in the underground market, and then like bond traders, they bundle them and resell them to criminals who want to rent the use of a botnet. This provides a great incentive for criminals to create even larger botnets.
3. Botnets use multiple automated propagation vectors to spread, including spam, worms, viruses and drive-by download attacks e.g. legitimate Web sites are often compromised with HTML tags that force a victim's browser to download JavaScript code from a server that's controlled by the attacker.
That code can launch a number of exploits against the unsuspecting PC. If any of the exploits is successful, the PC can become the next zombie on the botnet, making it easier than ever for the attacker to collect new nodes on his illicit network.
4. The malware that turns the PC into a bot can hide as a rootkit, making it exceptionally hard to detect and eradicate the malware. The Torpig botnet, as an example, implants Mebroot on the victim PC. Mebroot is a rootkit that replaces the system's Master Boot Record. Therefore, the PC is under the attacker's control even before the operating system loads.
5. Once installed, the malware can attack and nullify the very software that is supposed to prevent or at least detect the malware infection. Intel researchers report that botnet developers have begun to target the antivirus, local firewall and intrusion prevention/detection software and services.
The researchers identified at least two ways that a botnet blocked the security software from getting updates:
- A botnet changed the local DNS settings of the affected system to disable the antivirus software from reaching its update site.
- A botnet was actively detecting connection attempts to the update site and blocking them.
7. Botnets can be reprogrammed, allowing their missions to change. One day the botnet can be sending out spam, and the next day it can be told to collect credit card information from the infected PCs.
8. It used to be that bots generated a lot of "noise," making it easier to spot a compromised PC on a network. These days, some bots transmit little traffic, helping them to fly under the radar of log management systems. What's more, botnet traffic can masquerade as legitimate network traffic, making it hard to detect.
9. Legitimate applications such as Web browsers or office productivity tools can be compromised as part of the botnet's malware infection. For instance, the Torpig botnet injects malevolent DLLs into browsers, popular applications, e-mail clients, instant messengers and system programs. After the injection, Torpig can peruse and steal any data that is handled by these applications, including logon IDs and passwords.
If you were under the impression that botnets are no big deal, it's time to realise that they are a big threat and that they are to legitimate businesses and organisations. Now all you have to do is find ways to detect botnet infestations on your network.
Labels:
Botnet vectors,
code,
Cyberthieves,
developers anti-virus,
firewall,
spam,
Trojan,
worms
Subscribe to:
Posts (Atom)