Attacks/Breaches
3/5/2012
11:57 AM
50%
50%

Anonymous Allies Hit With Zeus Malware

Fraudsters steal hacktivist supporters' banking, webmail logins by modifying Anonymous attack tool with a hidden Trojan.

Anonymous: 10 Facts About The Hacktivist Group
Anonymous: 10 Facts About The Hacktivist Group
(click image for larger view and for slideshow)
Would-be Anonymous supporters, choose your attack tools carefully. That's because fraudsters have been disguising a banking Trojan application in a tool used by Anonymous for launching distributed denial-of-service (DDoS) attacks.

"Anonymous supporters have been deceived into installing Zeus botnet clients purportedly for the purpose of DoS attacks. The Zeus client does perform DoS attacks, but it doesn't stop there. It also steals the users' online banking credentials, webmail credentials, and cookies," according to a Symantec Security Response blog posted Sunday.

Symantec said it had traced related attacks back to January 20, 2012, which is the day that the FBI took down Megaupload. "An attacker took a popular PasteBin guide, used by Anonymous members for downloading and using the DoS tool Slowloris, and modified it," said Symantec. As of February 15, 2012, Symantec said that 470 Tweets still linked to the Pastebin post with the malicious link.

[ Hacktivism and fraud have increased security threats. Learn 10 Lessons From RSA Security Conference. ]

According to a site devoted to Slowloris, the DDoS tool "holds connections open by sending partial HTTP requests." But the Pastebin post--the original dates from May 2011--was modified to include a link to a Trojanized version of Slowloris. "When the Trojanized Slowloris tool is downloaded and executed by an Anonymous supporter, a Zeus (also known as Zbot) botnet client is installed," said Symantec. "After installation of the Zeus botnet client, the malware dropper attempts to conceal the infection by replacing itself with the real Slowloris DoS tool."

Zeus malware is designed to steal people's sensitive financial information, but is also often used by attackers to surreptitiously turn infected PCs--aka zombies--into nodes in a botnet. In other words, Anonymous attackers who download the malicious version of Slowloris could find their PCs participating in a DDoS attack, just not of their own choosing.

That's in addition to this implementation of Zeus being used, said Symantec, to transmit "cookies, online banking credentials, and webmail credentials" from an infected PC to the botnet owner's command-and-control server.

While Anonymous has generally expressed antagonism toward security firms--the hacktivist collective did create a spin-off dubbed AntiSec, after all--The Register spotted at least one pro-Anonymous Twitter channel picking up on Symantec's Slowloris malware warning, in a post that read, "Anonymous supporters tricked into installing Zeus trojan. This MUSTN'T happen. Be careful what you post and click on!"

This isn't the first warning related to the tools offered for participating in Anonymous DDoS campaigns. Last year, for example, LulzSec leader Sabu labeled the group's low orbit ion canon DDoS tool as a joke. What's curious with the malicious version of Slowloris discovered by Symantec, however, is that beyond stealing the financial details of whoever installs it, the software also still attacks websites targeted by Anonymous.

Security professionals often view compliance as a burden, but it doesn't have to be that way. In this report, we show the security team how to partner with the compliance pros. Download the report here. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Bprince
50%
50%
Bprince,
User Rank: Ninja
3/6/2012 | 3:43:10 AM
re: Anonymous Allies Hit With Zeus Malware
I doubt the Symantec warning is illegitimate feloanon...making the information public invites anyone with the know-how to analyze the program and see on their own if it's malicious.
Brian Prince, InformationWeek/Dark Reading Comment Moderator
feloanon
50%
50%
feloanon,
User Rank: Apprentice
3/5/2012 | 5:43:43 PM
re: Anonymous Allies Hit With Zeus Malware
don't by this crap
the link may or may not have been changed
but WE know better
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-2037
Published: 2014-11-26
Openswan 2.6.40 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads. NOTE: this vulnerability exists because of an incomplete fix for CVE 2013-6466.

CVE-2014-6609
Published: 2014-11-26
The res_pjsip_pubsub module in Asterisk Open Source 12.x before 12.5.1 allows remote authenticated users to cause a denial of service (crash) via crafted headers in a SIP SUBSCRIBE request for an event package.

CVE-2014-6610
Published: 2014-11-26
Asterisk Open Source 11.x before 11.12.1 and 12.x before 12.5.1 and Certified Asterisk 11.6 before 11.6-cert6, when using the res_fax_spandsp module, allows remote authenticated users to cause a denial of service (crash) via an out of call message, which is not properly handled in the ReceiveFax dia...

CVE-2014-7141
Published: 2014-11-26
The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and crash) via a crafted type in an (1) ICMP or (2) ICMP6 packet.

CVE-2014-7142
Published: 2014-11-26
The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (crash) via a crafted (1) ICMP or (2) ICMP6 packet size.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?