Jump to content

Zeus Trojan resurfaces


nsane.forums

Recommended Posts

medium.jpg

Websense researchers discover new wave of attacks targeted at government and military workers

Security vendor Websense is warning of a renewed spate of global attacks aimed at stealing information from staff in government and military departments via the notorious Zbot or Zeus Trojan.

The malware, which was originally designed and used to steal banking data, was used in a campaign targeting government workers in the US and UK at the beginning of the month.

This follow up attack involves a fake email purporting to be from a reputable figure within the Central Intelligence Agency, with the subject line: "Russian spear phishing attack against .mil and .gov employees".

"The spoofed emails capitalise on the last Zeus attack, and claim that installing theWindows update via the links provided will aid protection against Zeus attacks,' noted a Websense alert.

"The binary file downloaded from these links is identified as a Zeus bot and holds 35 per cent AV detection rate. Once again URLs in the email messages lead to a malicious file hosted on a compromised host, and also on a popular file hosting service."

According to Websense, after The Zeus Rootkit component is installed the command and control (C&C) server is contacted to download an encrypted configuration file.

Another data stealing component gets downloaded and installed from the same C &C, and then the bot starts to connect with a credential-based FTP server to upload stolen data.

view.gif View: Original Article

Link to comment
Share on other sites


  • Replies 3
  • Views 1.2k
  • Created
  • Last Reply

Get ready for a shut down of the internet people...

ESET will protect our digital world

Hahha they can't even protect themself :injured:

Link to comment
Share on other sites


Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...