วันศุกร์ที่ 19 กุมภาพันธ์ พ.ศ. 2553

Global cyberattacks hit firms, governments: NetWitness

Global cyberattacks hit firms, governments: NetWitness
By Manager Online 19 February 2010 13:52
This photo was taken in November 2009. Business and government computers had been plundered of information including log-in credentials for banking, email and social networking services, according to NetWitness.

by Glenn Chapman, February 19, 2010
SAN FRANCISCO (AFP) - Hackers have created a "dangerous new" network of virus-infected computers in 2,500 businesses and government agencies around the world, a US Internet security firm warned Thursday.

NetWitness dubbed the army of 75,000 zombie machines the "Kneber botnet" and said it was made using malicious ZeuS software that lets its masters steal information ranging from passwords to corporate or government secrets.

ZeuS malware has been increasingly used to siphon cash from financial institutions, with kits for customizing the larcenous programs hawked in the cyber underworld.

The code is usually slipped onto machines by tricking people into opening booby-trapped email attachments or clicking on tainted Internet links.

"These large-scale compromises of enterprise networks have reached epidemic levels," said NetWitness chief executive Amit Yoran, a former national cyber security division director at the US Department of Homeland Security.

"Cyber criminal elements, like the Kneber crew quietly and diligently target and compromise thousands of government and commercial organizations across the globe."

Computers compromised by the botnet let attackers take remote control of systems as well as mine them for valuable information about people's identities, financial transactions, and company activities.

NetWitness said it discovered the Kneber botnet in January while deploying an online monitoring system.

Investigation revealed that business and government computers had been plundered of information including log-in credentials for banking, email and social networking services, according to NetWitness.

Yoran said the scale of the attacks dwarfs the recent "Operation Aurora" cyberassault on Google and dozens of other firms.

The sophistication of the attack on Google has prompted suspicions of national level espionage although the culprits have yet to be identified.

Computer industry specialists subsequently said more than 30 companies were hit by those attackers.

The apparent online espionage prompted Google to vow it would stop bowing to Chinese censors and shut down its China search service if it cannot operate unfettered.

Google continues to filter searches in accordance with Chinese law while trying to negotiate a compromise with officials there.

"While Operation Aurora shed light on advanced threats from sponsored adversaries, the number of compromised companies and organizations pales in comparison to this single botnet," Yoran said.

More than half of the machines in the Kneber network were also infected with a Waledac code that instructs zombie machines to communicate with each other, making it harder to stamp out by essentially dispersing the command structure.

"It is 100 percent certain that many organizations have no idea they are victimized by these types of problems because they're just not tooled to see them on their networks," said NetWitness principal analyst Alex Cox.

"The Kneber botnet is just one category of advanced threat that organizations have been facing the past few years that they are still largely ignorant or blind to today."

Yoran told the Wall Street Journal that the hacking operation apparently began in late 2008 in Germany and grew to include using computers in China.

Evidence cited by NetWitness indicated the culprits may be Eastern European gangsters.

Workers at companies were tricked into visiting websites or opening email attachments that promised to clean viruses from computers but instead infected machines.
Acer Aspire AS1410-8414 11.6-Inch Sapphire Blue Laptop - 6 Hour Battery LifeDell D600 Laptop 1.6ghz 40gb DVD/CDRW B Grade Includes Genuine XP Professional restore cd!HP Pavilion DV4-1541US 14.1-Inch Espresso Laptop - Up to 4.25 Hours of Battery Life (Windows 7 Home Premium)Toshiba Satellite L505-S5993 TruBrite 15.6-Inch Grey/Black Laptop - 2 Hours 25 Minutes of Battery Life (Windows 7 Home Premium)Samsung NC10-13GB 10.1-Inch Blue Netbook - Up to 6 Hours of Battery LifeAcer Aspire One AOD150-1920 10.1-Inch Ruby Red Netbook - 6.5 Hour Battery LifeHP Pavilion DV6-1354US 15.6-Inch Black Laptop - Up to 4 Hours of Battery Life (Windows 7 Home Premium)Apple MacBook Pro MB990LL/A 13.3-Inch LaptopHP G60-530US 15.6-Inch Black/Silver Laptop - Up to 3.75 Hours of Battery Life (Windows 7 Home Premium)DELL LATITUDE D600 CENTRINO LAPTOP 512MB 30GB WIFI XP PRO 14" LCD LAPTOP
NEW Laptop/Notebook AC Adapter/Battery Char...Microsoft Bluetooth Notebook Mouse 5000 Mac...Dell Inspiron Mini 1011 10.1-Inch Obsidian ...Dell Inspiron 1545 15.6-Inch Jet Black Lapt...NEW Li-ion Laptop/Notebook Battery for Dell...Dell Inspiron iM10V-2734AWH Mini 10v 10.1-I...Dell Inspiron Mini 10 10.1-Inch Obsidian Bl... Dell Studio XPS 1640 15.6-Inch Obsidian Bla...Dell Inspiron 1545 15.6-Inch Jet Black Laptop - Up to 4 Hours 34 Minutes of Battery Life (Windows 7 Home Premium)Dell Inspiron i1545-4583JBK 1545 15.6-Inch Laptop (Jet Black)Dell Inspiron Mini 1011 10.1-Inch Obsidian Black Netbook - Up to 8 Hours 8 Minutes of Battery Life (Windows 7 Starter)NEW Laptop/Notebook AC Adapter/Battery Charger Power Supply Cord for Dell Inspiron 1150 1420 1501 1505 1520 1521 1525 1526 6000 6000D 6400 8500 8600Dell Inspiron 11 11.6-Inch Obsidian Black Laptop (Windows 7 Premium)Dell Inspiron 545 i545-2062NBK Desktop PC with 21.5-Inch Flat Panel Monitor (Piano Black)Dell Inspiron One 19 iO19-4834BGA 18.5-Inch Desktop PC (Polished Black with Graffiti Accents)Dell Studio XPS 1640 15.6-Inch Obsidian Black Laptop - Up to 3 Hours 8 Minutes of Battery Life (Windows 7 Home Premium)New Dell Latitude D620 D820 Keyboard UC172 DR160

ไม่มีความคิดเห็น:

แสดงความคิดเห็น