Security firm exposes massive crimeware server

By Matthew Broersma, ZDNet UK
Monday, August 11, 2008 05:55 AM

A Trojan horse command-and-control server discovered in June contained 50GB of stolen user account and financial details, including 9,000 bank and credit-card account credentials from around the world and 463,582 user account passwords, according to a report published at the Black Hat security conference in Las Vegas this week.

The server appears to have been the central control point for Coreflood, a password-stealing Trojan and botnet that has been quietly infiltrating corporate networks since 2001, according to Joe Stewart, director of malware research for security firm SecureWorks, which co-operated with Spamhaus in shutting down the server.

In a presentation at Black Hat, Stewart said an analysis of scripts left behind on the server indicated that the 50GB of material represented about one-quarter of the details that had been harvested, the rest having been deleted.

Coreflood has been known to security researchers for some time, but the broad scope of its operations has only come to light in recent weeks. In July, SecureWorks found that Coreflood, which began as a simple password-stealing Trojan, had added the ability to infect entire networks via a single administrator user account.

The Trojan poses more of a threat than more aggressive worms such as Storm, in part because its activities are practically invisible, Stewart said in the report. "Coreflood has managed to stay under the radar pretty effectively since 2004, with very few details available online about its activity in that time," he noted.

The botnet is still active, with its operators apparently having moved their base of operations from Wisconsin to Russia, Stewart said.

Of the usernames and passwords found on the server, 8,485 were for banks or credit unions, 3,233 were for credit cards and 151,000 were for e-mail accounts. Other password types included online retailers, share-trading accounts, online payment processors, mortgage lenders and payroll processors.

Among the organisations compromised were a major U.S. university hospital, with nearly 5,000 infected machines, a county school system, with 31,000 infections, a hotel chain, with more than 14,000 bots, and mortgage, pharmaceutical, oil and chemical companies. The Trojan also infected a U.S. state policy agency.

Stewart emphasized the meticulousness with which the attackers compromised networks. The Trojan spreads via drive-by downloads from infected Web sites, rather than more obvious e-mail messages or instant messenging messages and, once a user with administrative access to a network domain was compromised, the attackers used this access to spread to an entire domain.

The attackers did not rely on zero-day attacks, Stewart said. Instead, they used older exploits and were able to invade systems that had not been kept up to date with patches.

They used the server to verify the validity of bank-account information and, in one subdirectory, SecureWorks found information on 740 stolen accounts from a single financial institution. Those that had been tested for validity held an average of US$4,553.74 in savings and US$2,096.31 in their current account, based on which all 740 accounts could have held a total of more than US$2.5 million, Stewart said.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Use shades of gray to enhance scale in Excel

Microsoft Office Suite

Excel's palette is generous, but don't throw buckets of pigment all over your spreadsheets just because you can.


Read more »



Ultimate 2012 recovery site: the moon

Blog thumbnail

Have you seen the disaster movie "2012"? A friend from Control Risks and I did, and we reluctantly concluded we wouldn't be able to write off the cost of our..... by Nathaniel Forbes

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web