Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cloud
    • Cloud
    • Cybersecurity
    • Networking

    ‘Gameover’ Financial Botnet Compromises Nearly 700,000 Victims

    Written by

    eweekdev
    Published July 25, 2012
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      By: Robert Lemos

      A peer-to-peer botnet has infected more than 675,000 systems, including those at 14 of the top 20 Fortune 500 companies, according to research released July 25 at the Black Hat security conference.

      The botnet, known as Gameover, uses a private version of the Zeus framework, a collection of software components needed to compromise systems and manage the resulting network of computers. The operation targets the customers of banks in the United States, Europe and Asia, and demonstrates the complexity of such operations, said Brett Stone-Gross, a researcher with managed security services firm Dell Secureworks, who conducted the research.

      “There are definitely a number of newer botnets that are using peer-to-peer and moving away from the centralized control model,” Stone-Gross said. “There is really no infrastructure that law enforcement could go and take down without backtracking through a number of compromised systems. They have hidden their infrastructure really well.”

      The researcher has worked on analyzing the botnet since April, and the complex operation of the group behind Gameover.

      To infect more systems, the bot operators used a third-party spam botnet, known as Cutwail, to send out copies of legitimate emails that have been modified to spread their malware. People who click on a link in the email will be sent to a server that redirects them to another system hosting an exploit kit, which contains software that specializes in compromising systems. Known as the Blackhole exploit kit, the software is popular among cyber-criminals and attacks a variety of software vulnerabilities.

      “The Blackhole kit is not dropping the malware itself,” Stone-Gross said. “Instead, it is dropping a downloader known as Pony, which is interesting in that it is not just a loader, but it steals your HTTP, FTP and email credentials.”

      Once Pony installs Zeus on the compromised system, the software establishes a communications channel back to the attackers using peer-to-peer networking, which makes the botnet harder to dismantle, because there are no central command-and-control servers for authorities to shut down.

      Infected machines contact a hard-coded list of peers to get updates and commands. While some peer-to-peer botnets have been taken down by poisoning the peer list, it’s not an easy attack path, the researcher said. While researching the botnet, Stone-Gross has seen at least two attempts to disrupt the botnet fail.

      The researcher identified 678,205 unique bot IDs belonging to computers using 1.6 million unique IP addresses. Only about 15 percent of the botnet could be contacted from the Internet, Stone-Gross said. The others were likely behind firewalls, routers or proxies, he said.

      Like other Zeus variants, the Gameover botnet uses Web injects-a technique for injecting elements into a legitimate Website-to gather critical information from a banking customer that could be used to compromise their account. Nearly 22 percent of the infected computers were located in the United States, while Germany accounted for 7 percent and Italy for another 5 percent.

      The sophistication of the operation comes from a great deal of experience in mounting Zeus campaigns, says Stone-Gross.

      “There have been a bunch of private versions of Zeus, and these guys are pretty much the group behind all these private versions,” the researcher says.

      eweekdev
      eweekdev
      https://www.eweek.com

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.