Showing posts with label Zeus Banking Trojan. Show all posts
Showing posts with label Zeus Banking Trojan. Show all posts

Tuesday, 7 July 2015

Building Kit Of Malware That Dutch Banks Attacked Leaked



Researchers have found the kit on the Internet the malware was used in the past to attack Dutch banks. It is the KINS malware, which stands for "Kasper Internet Security Non ', a reference to an eponymous product of anti-virus firm Kaspersky Lab.

It is called a banking Trojan data for Internet banking attempting to steal, to subsequently join defraud. In addition, the malware can also steal passwords for different websites. In late June showed that of the 2.0 KINS "builder" and source code of the control was leaked, so discovered several researchers, including those from Malware Must Die! . They decided after internal consultation to make the discovery public, because they were mostly "bad guys" who knew of it, instead of the "good guys". So the malware can now be downloaded from various websites.

The researchers note that the source code of the malware itself is not leaked. It is the source of the control which information about infected computers can be collected and viewed. Through the "builder" which is also available online can through a few mouse clicks new instances of malware are generated and that can be a big problem, so they claim.

"This is very important information for the security community. The archive will be distributed on a large scale," the researchers said. They also ask others for help in countering the spread of the malware kit. KINS in 2013 was presented as a new digital bank robber. From examination of the Delft security company Fox-IT found that the Trojan horse in the source code of the notorious Zeus banking Trojan was founded and since 2011 it was used to attack banks, especially in Germany and the Netherlands.

Tuesday, 3 March 2015

Anti-virus company: Europol Operation Failed Against Botnet


The operation against the Ramnit botnet that Europol several European investigative services and security last week performed partly failed, causing hundreds of thousands of computers controlled by cybercriminals, according to the Russian anti-virus company Doctor Web.

In the operation were seized hundreds of domains that the botnet used to communicate with infected computers, as well as different servers. The Ramnit malware did over a period of almost five years in total to infect 3.2 million computers. The last half year were approximately 500,000 computers have been infected with the malware.

Doctor Web suggests that there are several variations of Ramnit are active, including one which since September 2011 has been announced. This version can steal all kinds of passwords and FTP programs would have on hundreds of thousands of computers are active every day. "Despite the message in the media about a successful operation against the Ramnit botnet, our analysts have no decrease seen botnets that monitors the anti-virus laboratory," the anti-virus company.

According to researchers from the virus fighter would definitely twelve Ramnit botnets operate. Two of these botnets exist together from more than 500,000 infected computers. "The figures show that the parties behind the operation to destroy the botnet Ramnit evidently not been able to turn off all servers of this botnet," as the researchers conclude whatsoever.

Wednesday, 25 February 2015

Large Botnet Achieved By Europol In The Air


Europol has partnered with European investigation services a large botnet off the air that had infected 3.2 million computers worldwide. It involves Ramnit botnet that for years was active and on infected computers include passwords booty made ​​and other data.

Computers were infected by opening links in spam emails and visiting infected websites. Ramnit is also a so-called "file infector" who .exe, .dll- and .html files on hard drives and connected storage devices infected. Once a computer became infected malware added the infected code in these files, and as soon as they were started spreading the infection further. Also were found public FTP servers that were used for distributing Ramnit.

In addition to investigative agencies from the Netherlands, Italy, Germany and Britain Europol coordinated the operation with Microsoft, Symantec and Anubis Networks . During the operation of the botnet Command & Control servers were turned off, and the 300 domains that were used to control infected computers.

"This successful operation demonstrates the importance of cooperation between international investigative agencies and private industry in combating cybercrime. We will remain committed to disable botnets and disrupting the infrastructure used by criminals for cyber crime," said Wil van Gemert, Deputy Director of Europol. Microsoft and Symantec have now been delivered solutions to remove the malware from infected computers.