Attacks/Breaches
3/5/2012
11:57 AM
Connect Directly
RSS
E-Mail
50%
50%

Anonymous Allies Hit With Zeus Malware

Fraudsters steal hacktivist supporters' banking, webmail logins by modifying Anonymous attack tool with a hidden Trojan.

Anonymous: 10 Facts About The Hacktivist Group
Anonymous: 10 Facts About The Hacktivist Group
(click image for larger view and for slideshow)
Would-be Anonymous supporters, choose your attack tools carefully. That's because fraudsters have been disguising a banking Trojan application in a tool used by Anonymous for launching distributed denial-of-service (DDoS) attacks.

"Anonymous supporters have been deceived into installing Zeus botnet clients purportedly for the purpose of DoS attacks. The Zeus client does perform DoS attacks, but it doesn't stop there. It also steals the users' online banking credentials, webmail credentials, and cookies," according to a Symantec Security Response blog posted Sunday.

Symantec said it had traced related attacks back to January 20, 2012, which is the day that the FBI took down Megaupload. "An attacker took a popular PasteBin guide, used by Anonymous members for downloading and using the DoS tool Slowloris, and modified it," said Symantec. As of February 15, 2012, Symantec said that 470 Tweets still linked to the Pastebin post with the malicious link.

[ Hacktivism and fraud have increased security threats. Learn 10 Lessons From RSA Security Conference. ]

According to a site devoted to Slowloris, the DDoS tool "holds connections open by sending partial HTTP requests." But the Pastebin post--the original dates from May 2011--was modified to include a link to a Trojanized version of Slowloris. "When the Trojanized Slowloris tool is downloaded and executed by an Anonymous supporter, a Zeus (also known as Zbot) botnet client is installed," said Symantec. "After installation of the Zeus botnet client, the malware dropper attempts to conceal the infection by replacing itself with the real Slowloris DoS tool."

Zeus malware is designed to steal people's sensitive financial information, but is also often used by attackers to surreptitiously turn infected PCs--aka zombies--into nodes in a botnet. In other words, Anonymous attackers who download the malicious version of Slowloris could find their PCs participating in a DDoS attack, just not of their own choosing.

That's in addition to this implementation of Zeus being used, said Symantec, to transmit "cookies, online banking credentials, and webmail credentials" from an infected PC to the botnet owner's command-and-control server.

While Anonymous has generally expressed antagonism toward security firms--the hacktivist collective did create a spin-off dubbed AntiSec, after all--The Register spotted at least one pro-Anonymous Twitter channel picking up on Symantec's Slowloris malware warning, in a post that read, "Anonymous supporters tricked into installing Zeus trojan. This MUSTN'T happen. Be careful what you post and click on!"

This isn't the first warning related to the tools offered for participating in Anonymous DDoS campaigns. Last year, for example, LulzSec leader Sabu labeled the group's low orbit ion canon DDoS tool as a joke. What's curious with the malicious version of Slowloris discovered by Symantec, however, is that beyond stealing the financial details of whoever installs it, the software also still attacks websites targeted by Anonymous.

Security professionals often view compliance as a burden, but it doesn't have to be that way. In this report, we show the security team how to partner with the compliance pros. Download the report here. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Bprince
50%
50%
Bprince,
User Rank: Ninja
3/6/2012 | 3:43:10 AM
re: Anonymous Allies Hit With Zeus Malware
I doubt the Symantec warning is illegitimate feloanon...making the information public invites anyone with the know-how to analyze the program and see on their own if it's malicious.
Brian Prince, InformationWeek/Dark Reading Comment Moderator
feloanon
50%
50%
feloanon,
User Rank: Apprentice
3/5/2012 | 5:43:43 PM
re: Anonymous Allies Hit With Zeus Malware
don't by this crap
the link may or may not have been changed
but WE know better
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-4840
Published: 2014-07-28
Unspecified vulnerability in HP and H3C VPN Firewall Module products SECPATH1000FE before 5.20.R3177 and SECBLADEFW before 5.20.R3177 allows remote attackers to cause a denial of service via unknown vectors.

CVE-2014-2974
Published: 2014-07-28
Cross-site request forgery (CSRF) vulnerability in php/user_account.php in Silver Peak VX through 6.2.4 allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts.

CVE-2014-2975
Published: 2014-07-28
Cross-site scripting (XSS) vulnerability in php/user_account.php in Silver Peak VX before 6.2.4 allows remote attackers to inject arbitrary web script or HTML via the user_id parameter.

CVE-2014-3303
Published: 2014-07-28
The web framework in Cisco WebEx Meetings Server does not properly restrict the content of query strings, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history, aka Bug ID CSCuj81713.

CVE-2014-3304
Published: 2014-07-28
The OutlookAction Class in Cisco WebEx Meetings Server allows remote attackers to enumerate user accounts by entering crafted URLs and examining the returned messages, aka Bug ID CSCuj81722.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Sara Peters hosts a conversation on Botnets and those who fight them.