Attacks/Breaches

1/5/2011
11:10 AM
50%
50%

Spam Attack Captures Government Data

A Zeus botnet variant disguised as a White House electronic greeting card netted numerous documents from U.S. agencies.

Top 10 Security Stories Of 2010
(click image for larger view)
Slideshow: Top 10 Security Stories Of 2010
A botnet-driven spam attack disguised as an electronic Christmas card from the White House netted data from numerous U.S. government agencies.

The attack was apparently launched a day or two before Christmas. Interestingly, the botnet behind the attack was a variant of the Zeus botnet, known as Kneber, which downloads a Perl script -- converted to an executable file -- that trolls for and copies documents to a server located in Belarus.

Security blogger Brian Krebs gained access to the server used in the attack, and found two gigabytes of PDFs, Word, and Excel documents, apparently from dozens of victims. Among the agencies that fell victim to the attack were the National Science Foundation's Office of Cyber Infrastructure; the Massachusetts State Police; the Moroccan government's Ministry of Industry, Commerce and New Technologies; and the intergovernmental Financial Action Task Force.

Kneber was first seen in February 2010, when security firm NetWitness estimated that the botnet had infected 75,000 PCs, many belonging to government agencies. At the time, the security firm reported that less than 10% of antivirus software were able to spot the advanced attack, and that no intrusion detection systems spotted the malware's peer-to-peer communications component.

Both appearances of Kneber have targeted not just government secrets, but also financial data, including "sites such as eBay, MySpace, and Microsoft, as well as online-payment processors, PayPal, and e-gold," said Alex Cox, principal research analyst for NetWitness, in a blog post.

Cox said the new version of Kneber appeared to be the work of the same attacker, as an analysis of the attack code found that two of the executables and three of the domain names were quite similar to the previous attack, and that the malware code itself was nearly identical in size.

As before, the malware searches for state secrets, as well as banking information and useful Web site credentials. "This evidence shows the continuing convergence of cyber-crime and cyber-espionage activities, and how they occasionally mirror or play off one another," said Cox.

But the attacker's backing or intent remains unclear. "Who is the end consumer of this information?" he asked.

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
New Mexico Man Sentenced on DDoS, Gun Charges
Dark Reading Staff 5/18/2018
Cracking 2FA: How It's Done and How to Stay Safe
Kelly Sheridan, Staff Editor, Dark Reading,  5/17/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Flash Poll
[Strategic Security Report] Navigating the Threat Intelligence Maze
[Strategic Security Report] Navigating the Threat Intelligence Maze
Most enterprises are using threat intel services, but many are still figuring out how to use the data they're collecting. In this Dark Reading survey we give you a look at what they're doing today - and where they hope to go.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-10428
PUBLISHED: 2018-05-23
ILIAS before 5.1.26, 5.2.x before 5.2.15, and 5.3.x before 5.3.4, due to inconsistencies in parameter handling, is vulnerable to various instances of reflected cross-site-scripting.
CVE-2018-6495
PUBLISHED: 2018-05-23
Cross-Site Scripting (XSS) in Micro Focus Universal CMDB, version 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.0, CMS, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1 and Micro Focus UCMDB Browser, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1. This vulnerability could be remotely exploited to al...
CVE-2018-10653
PUBLISHED: 2018-05-23
There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
CVE-2018-10654
PUBLISHED: 2018-05-23
There is a Hazelcast Library Java Deserialization Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
CVE-2018-10648
PUBLISHED: 2018-05-23
There are Unauthenticated File Upload Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.