Zeus (malware)

Zeus
TypeTrojan Horse
OriginJuly 2007

Zeus is a Trojan horse malware package that runs on versions of Microsoft Windows. It is often used to steal banking information by man-in-the-browser keystroke logging and form grabbing.[1] Zeus is spread mainly through drive-by downloads and phishing schemes. First identified in July 2007 when it was used to steal information from the United States Department of Transportation,[2] it became more widespread in March 2009. In June 2009 security company Prevx discovered that Zeus had compromised over 74,000 FTP accounts on websites of such companies as the Bank of America, NASA, Monster.com, ABC, Oracle, Play.com, Cisco, Amazon, and BusinessWeek.[3] Similarly to Koobface, Zeus has also been used to trick victims of technical support scams into giving the scam artists money through pop-up messages that claim the user has a virus, when in reality they might have no viruses at all. The scammers may use programs such as Command prompt or Event viewer to make the user believe that their computer is infected.[4]

Detection

Zeus is very difficult to detect even with up-to-date antivirus and other security software as it hides itself using stealth techniques.[5] It is considered that this is the primary reason why the Zeus malware has become the largest botnet on the Internet: Damballa estimated that the malware infected 3.6 million PCs in the U.S. in 2009.[6] Security experts are advising that businesses continue to offer training to users to teach them to not to click on hostile or suspicious links in emails or Web sites, and to keep antivirus protection up to date. Antivirus software does not claim to reliably prevent infection; for example Symantec's Browser Protection says that it can prevent "some infection attempts".[7]

FBI crackdown

FBI: The Zeus Fraud Scheme

In October 2010 the US FBI announced that hackers in Eastern Europe had managed to infect computers around the world using Zeus.[8] The virus was distributed in an e-mail, and when targeted individuals at businesses and municipalities opened the e-mail, the trojan software installed itself on the victimized computer, secretly capturing passwords, account numbers, and other data used to log into online banking accounts.

The hackers then used this information to take over the victims’ bank accounts and make unauthorized transfers of thousands of dollars at a time, often routing the funds to other accounts controlled by a network of money mules, paid a commission. Many of the U.S. money mules were recruited from overseas. They created bank accounts using fake documents and false names. Once the money was in the accounts, the mules would either wire it back to their bosses in Eastern Europe, or withdraw it in cash and smuggle it out of the country.[9]

More than 100 people were arrested on charges of conspiracy to commit bank fraud and money laundering, over 90 in the US, and the others in the UK and Ukraine.[10] Members of the ring had stolen $70 million.

In 2013 Hamza Bendelladj, known as Bx1 online, was arrested in Thailand[11] and deported to Atlanta, Georgia, USA. Early reports said that he was the mastermind behind ZeuS. He was accused of operating SpyEye (a bot functionally similar to ZeuS) botnets, and suspected of also operating ZeuS botnets. He was charged with several counts of wire fraud and computer fraud and abuse.[12] Court papers allege that from 2009 to 2011 Bendelladj and others "developed, marketed, and sold various versions of the SpyEye virus and component parts on the Internet and allowed cybercriminals to customize their purchases to include tailor-made methods of obtaining victims’ personal and financial information". It was also alleged that Bendelladj advertised SpyEye on Internet forums devoted to cyber- and other crimes and operated Command and Control servers.[13] The charges in Georgia relate only to SpyEye, as a SpyEye botnet control server was based in Atlanta.

Possible retirement of creator

In late 2010, a number of Internet security vendors including McAfee and Internet Identity claimed that the creator of Zeus had said that he was retiring and had given the source code and rights to sell Zeus to his biggest competitor, the creator of the SpyEye trojan. However, those same experts warned the retirement was a ruse and expect the developer to return with new tricks.[14][15]

See also

References

  1. ^ Abrams, Lawrence. "CryptoLocker Ransomware Information Guide and FAQ". Bleeping Computer. Retrieved 25 October 2013.
  2. ^ Jim Finkle (17 July 2007). "Hackers steal U.S. government, corporate data from PCs". Reuters. Retrieved 17 November 2009.
  3. ^ Steve Ragan (29 June 2009). "ZBot data dump discovered with over 74,000 FTP credentials". The Tech Herald. Archived from the original on 25 November 2009. Retrieved 17 November 2009.
  4. ^ "How to Recognize a Fake Virus Warning". Retrieved 28 July 2016.
  5. ^ "ZeuS Banking Trojan Report". Dell SecuWorks. 10 March 2010. Retrieved 2 March 2016.
  6. ^ "The Hunt for the Financial Industry's Most-Wanted Hacker". Bloomberg. Bloomberg Business. 18 June 2015. Retrieved 2 March 2016.
  7. ^ "Trojan.Zbot". Symantec. Archived from the original on 30 January 2010. Retrieved 19 February 2010.
  8. ^ "Cyber Banking Fraud". The Federal Bureau of Investigation. Retrieved 2 March 2016.
  9. ^ FBI (1 October 2010). "CYBER BANKING FRAUD Global Partnerships Lead to Major Arrests". Archived from the original on 3 October 2010. Retrieved 2 October 2010.
  10. ^ BBC (1 October 2010). "More than 100 arrests, as FBI uncovers cyber crime ring". BBC News. Retrieved 2 October 2010.
  11. ^ Al Jazeera (21 September 2015). "Hamza Bendelladj: Is the Algerian hacker a hero?". AJE News. Retrieved 21 March 2016.
  12. ^ Zetter, Kim. "Alleged 'SpyEye' Botmaster Ends Up in America, Handcuffs, Kim Zetter, Wired, 3 May 2013". Wired. Wired.com. Retrieved 30 January 2014.
  13. ^ "Alleged "SpyEye" mastermind extradited to US, Lisa Vaas, 7 May 2013, Sophos nakedsecurity". Nakedsecurity.sophos.com. 7 May 2013. Retrieved 30 January 2014.
  14. ^ Diane Bartz (29 October 2010). "Top hacker "retires"; experts brace for his return". Reuters. Retrieved 16 December 2010.
  15. ^ Internet Identity (6 December 2010). "Growth in Social Networking, Mobile and Infrastructure Attacks Threaten Corporate Security in 2011". Yahoo! Finance. Retrieved 16 December 2010.

Read other articles:

Stasiun Ashisawa芦沢駅Tampak luar Stasiun Ashisawa pada Mei 2005Lokasi1012 Ashizawa, Obanazawa-shi, Yamagata-ken 999-4554JepangKoordinat38°39′20″N 140°21′40″E / 38.655489°N 140.361064°E / 38.655489; 140.361064Koordinat: 38°39′20″N 140°21′40″E / 38.655489°N 140.361064°E / 38.655489; 140.361064Pengelola JR EastJalur■ Jalur Utama ŌuLetak dari pangkal133.7 km dari FukushimaJumlah peron2 peron siisInformasi lainStatusMem...

 

島谷 ひとみ 2015年撮影基本情報出生名 島谷 瞳別名 Blue-Eye-Land生誕 (1980-09-04) 1980年9月4日(43歳)出身地 広島県呉市(旧安芸郡音戸町)学歴 清水ヶ丘高等学校卒業ジャンル J-POP、演歌(初期)職業 歌手、モデル、女優、声優担当楽器 ボーカル活動期間 1999年 -レーベル avex trax(1999年 - 2021年)AI.R LAND RECORD (Daiki Sound)(2021年 - )事務所 バーニングプロダクション→Grick→個...

 

هذه المقالة يتيمة إذ تصل إليها مقالات أخرى قليلة جدًا. فضلًا، ساعد بإضافة وصلة إليها في مقالات متعلقة بها. (نوفمبر 2019) جيف ليمان   معلومات شخصية الميلاد سنة 1975 (العمر 47–48 سنة)  تورونتو  مواطنة كندا  الحياة العملية المهنة اقتصادي  تعديل مصدري - تعديل   جيف ليما...

Cytotoxic T-lymphocyte-associated protein 4 Structure of murine CTLA4 (CD152) التراكيب المتوفرة بنك بيانات البروتين بحث أورثولوغ: PDBe, RCSB قائمة رموز معرفات بنك بيانات البروتين 1AH1, 1H6E, 1I85, 1I8L, 2X44, 3BX7, 3OSK المعرفاتالرمز، (أو الرموز) CTLA4; ALPS5; CD; CD152; CELIAC3; CTLA-4; GRD4; GSE; IDDM12معرفات خارجية OMIM: 123890 MGI: 88556 هومولوجين: 3820 ب...

 

Cet article est une ébauche concernant le chemin de fer et la Finlande. Vous pouvez partager vos connaissances en l’améliorant (comment ?) selon les recommandations des projets correspondants. Lignede Murtomäki à Otanmäki Pays Finlande Villes desservies Kajaani Historique Mise en service 1953 Concessionnaire Agence des infrastructures de transport de Finlande Caractéristiques techniques Longueur 25,7 km km Écartement large (1 524 mm) Électrification Non électrif...

 

 Główny artykuł: Gimnastyka na Letnich Igrzyskach Olimpijskich 1912. Letnie Igrzyska Olimpijskie 1912GimnastykaWielobój drużynowy mężczyzn w systemie wolnym Norwegia Finlandia Dania Gimnastyka na Letnich Igrzyskach Olimpijskich 1912 wielobój indywidualny mężczyźni wielobój drużynowy mężczyźni wielobój drużynowy(system wolny) mężczyźni wielobój drużynowy(system szwedzki) mężczyźni Wielobój drużynowy mężczyzn w systemie wolnym był jedną z czterech konkurencj...

  هذه المقالة عن مركب كيميائي. لكربون، طالع كربون (توضيح). كربونات Ball-and-stick model of the carbonate anion الاسم النظامي (IUPAC) Carbonate تسمية الاتحاد الدولي للكيمياء Trioxidocarbonate[1]:127 المعرفات رقم CAS 3812-32-6 بوب كيم (PubChem) 19660 مواصفات الإدخال النصي المبسط للجزيئات C(=O)([O-])[O-] المعرف الكيميائي ال...

 

2019 British filmRomantic ComedyFilm posterDirected byElizabeth SankeyProduced by Jeremy Warmsley Oskar Pimlott Maria Chiara Ventura Edited byElizabeth SankeyMusic bySummer Camp, Jeremy WarmsleyRelease dates 25 January 2019 (2019-01-25) (IFFR) 9 March 2020 (2020-03-09) (UK) Running time78 minutes.[1]CountryUnited KingdomLanguageEnglish Romantic Comedy is a 2019 British documentary film about romantic comedies, directed, edited and narrated by Eliz...

 

Кубок португальської ліги 2022—2023 Подробиці Дата проведення 19 листопада 2022 — 28 січня 2023 Кількість учасників 34 Призові місця  Чемпіон Порту (1-й раз) Віцечемпіон Спортінг Статистика Бомбардир(и) Паулінью (8 м'ячів) Зіграно матчів 63 Забито голів 166 (2.63 за матч) ← 2021–2...

Experimental drug for the treatment of achondroplasia VosoritideClinical dataTrade namesVoxzogoOther namesBMN-111License data US DailyMed: Vosoritide Pregnancycategory AU: B2[1][2] Routes ofadministrationSubcutaneous injectionATC codeM05BX07 (WHO) Legal statusLegal status AU: S4 (Prescription only)[1] US: ℞-only[3][4] EU: Rx-only[5] IdentifiersCAS Number1480724-61-5DrugBankDB11928ChemSpider44210446UNII7S...

 

Film festival 2014 Toronto International Film FestivalFestival posterOpening filmThe JudgeClosing filmA Little ChaosLocationToronto, Ontario, CanadaFounded1976AwardsThe Imitation Game (People's Choice Award)Hosted byToronto International Film Festival GroupNo. of films393 filmsFestival date4–14 September 2014Websitetiff.net The 39th annual Toronto International Film Festival, the 39th event in the Toronto International Film Festival series, was held in Canada from 4–14 September 2014.[...

 

Slovenian tennis player Blaž RolaCountry (sports) SloveniaResidencePtuj, SloveniaBorn (1990-10-05) 5 October 1990 (age 33)Ptuj, SR Slovenia, YugoslaviaHeight1.93 m (6 ft 4 in)Turned pro2013PlaysLeft-handed (two-handed backhand)CollegeOhio State UniversityPrize money$1,132,124SinglesCareer record15–23Career titles0Highest rankingNo. 78 (5 January 2015)Current rankingNo. 478 (31 July 2023)Grand Slam singles resultsAustralian Open2R (2014...

Chemical that inhibits the use of a metabolite The drug methotrexate (right) is an antimetabolite that interferes with the metabolism of folic acid (left). An antimetabolite is a chemical that inhibits the use of a metabolite, which is another chemical that is part of normal metabolism.[1] Such substances are often similar in structure to the metabolite that they interfere with, such as the antifolates that interfere with the use of folic acid; thus, competitive inhibition can occur, ...

 

Hungarian handball player The native form of this personal name is Planéta Szimonetta. This article uses Western name order when mentioning individuals. Szimonetta Planéta Planéta in 2017Personal informationBorn (1993-12-12) 12 December 1993 (age 29)Kazincbarcika, HungaryNationality HungarianHeight 1.98 m (6 ft 6 in)Playing position Right backClub informationCurrent club Debreceni VSCNumber 43Youth careerYears Team2006–2009 Győri ETO KCSenior clubsYears Team2009...

 

الصفحه دى يتيمه, حاول تضيفلها مقالات متعلقه لينكات فى صفحات تانيه متعلقه بيها. ستانلى سپوركين معلومات شخصيه الميلاد 7 فبراير 1932  فيلادلفيا  الوفاة 23 مارس 2020 (88 سنة)[1]  روكفيل, ماريلاند[1]  مواطنه امريكا  الحياه العمليه المدرسه الام جامعة ييلجامعة ولايه ب...

RomaMusim 1992–93PresidenGiuseppe CiarrapicoManajerVujadin BoškovStadionStadio OlimpicoSerie A10Coppa ItaliaRunners-upUEFA CupPerempat finalPencetak gol terbanyakLiga: Giuseppe Giannini (9)Seluruh kompetisi: Giuseppe Giannini (16)← 1991–92 1993–94 →Akibat musim yang semenjana, Associazione Sportiva Roma kehilangan posisinya sebagai tim terbaik di kota Roma. Dibawah kepemimpinan manajer baru Vujadin Boškov - yang sebelumnya sukses bersama Sampdoria meraih gelar domestik dan mencapa...

 

Tibni (Ibrani: תִּבְנִיcode: he is deprecated Tib-ni manusia jerami[1]) bin Ginat adalah satu dari 2 orang (calon lain: Omri) yang diangkat rakyat Israel untuk menjadi raja Kerajaan Israel (Samaria) menurut Alkitab Ibrani. Meskipun rakyat yang mengikuti Omri lebih kuat daripada rakyat yang mengikuti Tibni, baru setelah Tibni mati 5 tahun kemudian, Omri menjadi raja.[2] Tibni diduga berasal dari Yerahmeel, seperti saingannya, Omri.[3] Perhitungan waktu William F...

 

Delta Force Black Hawk DownDezvoltator(i)NovaLogic[*][[NovaLogic (American video game developer)|​]]  Editor(i)NovaLogic[*][[NovaLogic (American video game developer)|​]]  Distribuitor(i)SteamGOG.com[1]  Designer(i)NovaLogic[*][[NovaLogic (American video game developer)|​]]  SerieDelta Force[*][[Delta Force (video game series)|​]]  PlatformăXboxPlayStation 2Microsoft Windows[2]macOS  Dată lansare24 martie 2003  Genur...

Smooth Collie Tricolour Collie with training dumbbell.Otros nombres Collie (Smooth Coat)Región de origen Escocia EscociaCaracterísticasTipo perroPeso 20,5 kilogramosOtros datosFederaciones FCI,[1]​ AKC,[2]​ ANKC,[3]​ CKC,[4]​ KC,[5]​ NZKC,[6]​ UKC[7]​[editar datos en Wikidata] Imagen de 1915 Azul merlé El Smooth Collie es una raza de perro desarrollada originariamente como perro pastor. Se trata de una versión de pelo corto del Coll...

 

As referências deste artigo necessitam de formatação. Por favor, utilize fontes apropriadas contendo título, autor e data para que o verbete permaneça verificável. (Dezembro de 2021) Campeonato Ucraniano de Futebol Dados gerais Organização UEFA Edições 24 Local de disputa  Ucrânia Número de equipes 16 Sistema Temporada, pontos corridos Dados históricos Primeiro vencedor Tavriya Simferopol (1991–92) Último vencedor Shakhtar (2022–23) Maior vencedor Dínamo de Kiev (16 t...

 

Strategi Solo vs Squad di Free Fire: Cara Menang Mudah!