republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » IM Rootkit Tracked To Mid East Group
Search Topic:
Uniqs:
225
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Norton Internet Security Problem! »
« Just a precaution, HJT log included  
AuthorAll Replies

TeMerc

join:2004-01-22
Phoenix, AZ

 IM Rootkit Tracked To Mid East Group

The Rootkit powered Botnet

Paperghost wrote:
"The great internet shakedown has begun, and to coin a phrase, it's clobberin' time."

Yet consider what our team has been able to ferret out lately -

A rather nasty IM virus tracked, jacked and nailed like a punk.

The "fake" Google Toolbar, traced back to IM and also tracked right back to 2003.

The notorious IM Rootkit, so hot they covered it twice in two days on Slashdot. Ye Gods.

And, after further investigation on the AIM rootkit story, we are fairly confident we have located the group behind this thing and have turned the information over to the FBI and other federal agencies.

What is scary here, is the potential for mass damage that we have seen through monitoring this group (based in the Middle East) nearly 24/7. They are slowly but surely building one of those huge botnets we all know and love, spread across the globe and it seems the lockx rootkit was simply the beach-head - the first wave. Naturally, we can only speculate and often researchers have to do just that - a good researcher knows their enemy, and follows a hunch when little evidence is on the table.

They spread the lockx rootkit via IM, hidden in with a big pile of advertising software. As I predicted at the time, the Adware stuff was likely just a decoy, to distract from the rootkit that came in the package.

Over 17,000 users were found to be compromised on a single server, and we found lots of those worldwide.

We spread all new kinds of malware, self-extracting zipfiles, altered file-names, modified infections ripped from other sources of distribution.....and this stuff does all of the below and then some:

Can steal your browser auto-complete data which may leak confidential personal information

Gain access to Microsoft Outlook Express

Open browsers to launch a denial of service attack, and/or

Download additional malicious applications

As you can see, the scale and ambition of this one is truly frightening. It also does not bode well if you subscribe to the “Porterism” kind of future. A mass of Botnets can wreak havoc on a world that is networked like never before - banks, emergency services, vital communications - you get the picture.

For more information on what to expect from this thing, check out the official FaceTime press release here:
»facetime.com/pr/pr051117.aspx

Stay frosty, kids.


Full Read @ VitalSecurity.org
»www.vitalsecurity.org/2005/11/ro···net.html
Forums » Up and Running » Security » SecurityNorton Internet Security Problem! »
« Just a precaution, HJT log included  


Thursday, 10-Dec 15:57:13 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [200] Sprint Sued For Distracted Driving Death
· [131] AT&T Launching New 24 Mbps U-Verse Tier
· [85] AT&T Hints At Usage-Based iPhone Data Pricing
· [82] 3G Network Test Says AT&T Is Tops
· [72] Mediacom Unveils 105 Mbps Pricing
· [71] WPA Cracker: Test WPA-PSK Networks In 20 Minutes
· [66] Sprint Poised For A Turnaround?
· [51] The Future Of Wi-Fi Is Bright
· [50] Average American Consumes 34 Gigabytes Daily
· [47] Site Leaks Yahoo, Verizon Fed Data Share Pricing
Most people now reading
· [WIN7] Well, I was dumb, but do I have recourse? [Microsoft Help]
· New Mediacom Email [Mediacom]
· Cross Server Dungeon Experience [World of Warcraft]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· malware has been found hidden inside an Ubuntu screensaver [Security]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· CRTC hearing on Monday [TekSavvy]
· So what's your impressions of Lich King so far.... [World of Warcraft]
· Windows 7 boot manager editing questions [Microsoft Help]
· New 5 mans full walk through [World of Warcraft]