Translate

Posts mit dem Label Keylogger werden angezeigt. Alle Posts anzeigen
Posts mit dem Label Keylogger werden angezeigt. Alle Posts anzeigen

12/07/2013

Pony Botnet Controller - Facebook, Google, Twitter, Yahoo:
Almost 2 Million Usernames & Passwords Stolen in a Mass Hack

Almost 2 million accounts on Facebook, Google, Twitter, Yahoo and other social media and Internet sites have been breached, according to a Chicago-based cybersecurity firm.


The hackers stole 1.58 million website login credentials and 320.000 e-mail account credentials, among other items, the firm Trustwave reported in a blogpost. Included in the hacks were thefts of 318.121 passwords from Facebook, 59.549 from Yahoo, 54.437 from Google, 21.708 from Twitter and
8.490 from LinkedIn. The list also includes 7.978 from ADP, the payroll service provider.

According to Trustwave, "Payroll services accounts could actually have direct financial repercussions."

Stolen Passwords by Day
Most of those stolen passwords were from the Netherlands, followed by Thailand, Germany, Singapore, Indonesia and the United States, which accounted for 859 reports from machines and 1.943 passwords, according to Trustwave. All inn all, just over 100 countries were affected, and Trustwave said this shows the attack is "fairly global."



The hacking began October 21st 2013 and might still be taking place, according to a CNN article, on this case.

The massive data crack was a result of keylogging software maliciously installed on an untold number of CPUs around the world, according to researchers at Trustwave. The Malware was capturing log-in credentials for key websites over the past month and sending those usernames and passwords to a server controlled by the hackers. On November 24th 2013, Trustwave Analysts tracked that server, located in the Netherlands. Google itself declined to comment on this subject.

John Miller, a security research manager at Trustwave, told CNN, "We don't have evidence they logged into these accounts, but they probably did." (So what now....?)

Miller said the team doesn't yet know how the virus got onto so many personal computers. The hackers set up the keylogging software to rout information through a proxy server, so it's impossible to track down which computers are infected.

Among the compromised data are about 41.000 credentials used to connect to File Transfer Protocol (FTP, the standard network used when transferring big files) and 6.000 remote log-ins.

 There are several other servers Trustwave has not yet tracked down, Miller said. ADP, Facebook, LinkedIn and Twitter told CNN they have notified users and reset passwords for compromised accounts. Google declined to comment and Yahoo did not respond immediately.

In compiling the data, Trustwave also discovered that many users are doing just what computer specialists advise against, using simplistic passwords that can easily be guessed. For instance, the top five passwords Trustwave found in researching the breaches were: 123456, 123456789, 1234, password and 12345.

Read the whole Blogpost from Trustwave @:
Look What I Found: Moar Pony!

SOURCE: Money CNN

11/26/2013

Symantec:
Blackshades Remote Access Tool (RAT) still being bargained

Cybercriminals are increasingly using the Blackshades Remote Access Tool (RAT), a malicious program whose source code was leaked three years ago, according to an analysis by Symantec.


Santiago Cortes, a security response engineer at Symantec, wrote in a blog post, that Blackshades, which Symantec identifies as W32.Shadesrat”, has been infecting more MS Windows computers and is being controlled by many hundreds of CnC Botnets worldwide, despite the alleged arrest of Michael Hogue (a/k/a “xVisceral,”) in June 2012, the author who wrote the malicious code (program, tool).



As already mentioned, Blackshades is a Remote Access Tool (RAT) that collects usernames and passwords for email and/or Web services, Instant Messaging applications (like ICQ), FTP clients and many more. It has been sold on Black Hat Forums since at least 2010.

It’s common for hackers to use RAT’s, which can be used to upload other Malicious Software to a computer or to destroy and manipulate files. To avoid AV-Software, the program itself is often frequently modified, that is why a Malware Variant changes its name in the eyes of AV-Softwareanalytics, for instance this file is called W32.Shadesrat.C, usually means (like in this case), it’s the 3rd (A,B,C) modified (Variant) or, Generation, if you want so.

In his post, Cortes mentions that Lithuania and the United States have the highest number of command-and-control servers. Mostly all of those "Servers" have hosted exploit kits at some point in time, a type of baited trap that delivers additional malware to CPU’s with software vulnerabilities (don’t forget to update). Referring to Blackshades, Cortes says, that India, the U.S. and the U.K. have the most computers infected with this RAT.

Cortes writes:

“The distribution of the threats suggests that the attackers attempted to infect as many computers as possible, the attackers do not seem to have targeted specific people or companies.”

Earlier this year, Symantec articled in a blog that a license to use Blackshades may cost around $40 to $100 a year.


To this graph, i’d like to point out to 2 earlier Posts of Malicious IPs , that likely shows how involved the small country Luxembourg, in the heart of Europe, is, inbetween Malicious Activity:


Symantec wrote as well that Blackshades had been promoted on underground forums by a person going by the nickname “xVisceral,”


In June 2012, the U.S. Attorney’s Office for the Southern District of New York announced the arrest of Michael Hogue (Rogue?) in Tucson, Arizona. Hogue was arrested with 23 others in a “carding” scheme, which involved trafficking in financial details.


FBI Article: Two-Year FBI Undercover “Carding” Operation Protected Over 400,000 Potential Cyber Crime Victims and Prevented Over $205 Million in Losses

He was charged with conspiracy to commit computer hacking and distribution of malware.