Microsoft Targets Zeus Botnets With Financial Services Partners

Published: Mar 26, 2012
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Microsoft€™s Digital Crimes Unit and a handful of financial-services partners undertook a coordinated action against Zeus botnets March 23, shutting down command-and-control servers in Pennsylvania and Illinois.

Microsoft€™s partners in the operation included the Financial Services-Information Sharing and Analysis Center (FS-ISAC) and NACHA-The Electronic Payments Association, along with Kyrus Tech Inc. U.S. Marshals escorted Microsoft personnel during the actual seizure of the hardware at the hosting locations. Despite the action, however, Zeus botnets still exist in other parts of the globe.

€œFor this action€”code-named Operation b71€”we focused on botnets using Zeus, SpyEye and Ice-IX variants of the Zeus family of malware,€ Richard Domingues Boscovich, senior attorney for Microsoft€™s Digital Crimes Unit, wrote in a March 25 posting on The Official Microsoft Blog. €œOur goal was a strategic disruption of operations to mitigate the threat in order to cause long-term damage to the cyber-criminal organization that relies on these botnets for illicit gain.€ Microsoft continues to monitor some 800 domains related to the seized servers, in turn, allowing the company to identify a large number of PCs infected with the malware.

Zeus malware uses keylogging in order to access user names and passwords. From there, a cyber-criminal can steal victims€™ online identities. €œMicrosoft researchers found that once a computer is infected with Zeus, the malware automatically starts keylogging when a person types in the name of a financial or e-commerce institution,€ Boscovich wrote, €œallowing criminals to gain access to people€™s online accounts from that point forward.€

Microsoft claims some 13 million suspected Zeus infections worldwide, with 3 million of them in the United States. The company filed suit March 19 in the United States District Court for the Eastern District of New York against €œJohn Does 1-39,€ which it claims have control over the Internet Domains and IP addresses linked to Zeus botnets. In doing so, Microsoft follows a successful pattern established in the Waledac, Rustock and Kelihos botnet takedowns, all of which involved a courtroom aspect in addition to seizing command-and-control servers.

€œWe don€™t expect this action to have wiped out every Zeus botnet operating in the world,€ Boscovich added. €œHowever, together, we have proactively disrupted some of the most harmful botnets, and we expect this effort will significantly impact the cyber-criminal underworld for quite some time.€

Follow Nicholas Kolakowski on Twitter

Nicholas Kolakowski

Nicholas Kolakowski

Content Writer

Nicholas Kolakowski is a staff editor at eWEEK, covering Microsoft and other companies in the enterprise space, as well as evolving technology such as tablet PCs. His work has appeared in The Washington Post, Playboy, WebMD, AARP the Magazine, AutoWeek, Washington City Paper, Trader Monthly, and Private Air.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。