Zeus trojan nets 20-year old $3.2 million

Powered by SC Magazine
 

US tracking Russian hacker.

A hacker known in the cybercriminal underground as “soldier” has stolen $3.2 million from major US corporations in the past six months, according to researchers at anti-virus firm Trend Micro.

The attacker, believed to be in his early 20s and residing in Russia, used toolkits to plunder millions of dollars from corporate bank accounts since January.

The hacker oversees a network of money mules and accomplices, who are believed to reside in West Hollywood and Venice, California.

Trend researchers have been investigating the hacker's operations since April and have notified federal authorities, Trend Micro threat research manager Jamie Yaneza said.

Organisationa cross a wide number of industries including military, educational and research institutions; airports; banks; and automobile, media and technology firms, were affected.

Yaneza said he could not name the victim corporations due to an active federal law enforcement investigation.

A number of home users have also been victimised, he said. While nearly all of the victims are located in the United States, a small amount reside in some 90 countries, including Britain, Brazil, Mexico, Thailand, Turkey, Saudi Arabia, India, Romania, and Canada.

Yaneza said the hacker heavily relied on the SpyEye and Zeus tookits, which come with full support and regular updates and are available for purchase on black market.

Starting around January, the intruder began using Zeus to compromise users' systems via drive-by downloads.

Once compromised, computers were infected with banking trojans that automated online banking fraud, Yaneza said. The malware is capable of siphoning small increments of money at a time out of bank accounts without users noticing.

SpyEye and Zeus are routinely used to steal credentials from high-profile sites such as Facebook, Yahoo, Google, eBay, Amazon, Twitter, PayPal and Skype.

To increase the number of infected computers under his control, the hacker began using the stolen funds accrued from the operation to lease out infected machines from other criminals.

Between April 19 and June 29, the hacker amassed a botnet of more than 25,000 systems, 57 percent of which were running Windows XP, according to Trend Micro researchers.

Some 4500 infected systems were running the latest Windows operating system, Windows 7.

“Given that the tools are being sold on the underground, this is just one example of what dozens [of criminals] could be doing,” Yaneza said.

This article originally appeared at scmagazineus.com

Copyright © SC Magazine, US edition


Zeus trojan nets 20-year old $3.2 million
 
 
 
Top Stories
Westpac committed to core banking plan
[Blog post] Now with leadership.
 
The True Cost of BYOD - 2014 survey
Twelve months on from our first study, is BYOD a better proposition?
 
Photos: Unboxing the Magnus supercomputer
Pawsey's biggest beast slots into place.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
What is delaying adoption of public cloud in your organisation?







   |   View results
Lock-in concerns
  29%
 
Application integration concerns
  3%
 
Security and compliance concerns
  27%
 
Unreliable network infrastructure
  9%
 
Data sovereignty concerns
  22%
 
Lack of stakeholder support
  3%
 
Protecting on-premise IT jobs
  4%
 
Difficulty transitioning CapEx budget into OpEx
  3%
TOTAL VOTES: 1141

Vote