Risk
10/15/2010
04:16 PM
George V. Hulme
George V. Hulme
Commentary
Connect Directly
RSS
E-Mail
50%
50%

Microsoft Steps Up To Dethrone Zeus

Microsoft is throwing another punch at this most nasty and extremely active botnet.

Microsoft is throwing another punch at this most nasty and extremely active botnet.Early this month there was a flurry of arrests surrounding a cybercrime gang utilizing the dangerous triad of exploits, botnets, and money mules.

From Feds Bust Zeus Financial Cybercrime Ring earlier this month:

Federal and state authorities announced Thursday that they have charged numerous people in connection with a global cybercrime scheme using the Zeus financial malware toolkit to steal $3 million from U.S. bank accounts. The investigation was dubbed "Operation ACHing Mule," alluding to the attackers' use of Automatic Clearing House fraud, as well as "money mules" to move money.

According to Manhattan district attorney Cyrus Vance Jr., "this advanced cybercrime ring is a disturbing example of organized crime in the twenty-first century -- high-tech and widespread."

To help fight the Zeus botnet, Microsoft has added Zeus detection to its Malicious Software Removal Tool, or MSRT. MSRT is a free anti-malware tool that is released on patch Tuesday and scans most versions of Microsoft Windows for malware to disinfect.

From Microsoft's Malware Protection Center blog, it does seem the software maker is bent on ridding the world of as many Zeus infections as possible:

This family is quite prolific even if the intent behind some of the botnets is unclear. That said, we find ourselves knocking on Zbot's door this month, and we're glad we are. Zbot is the latest addition to MSRT's ever-growing list of malware, and we hope to continue protecting the Windows ecosystem with this new family firmly in our sights.

However, as Dark Reading points out in this post, Zeus isn't the only threat, botnets such as Bugat and Carberp also pose serious threats.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0103
Published: 2014-07-29
WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitive information by reading the PHP session files.

CVE-2014-0475
Published: 2014-07-29
Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2.20 allow context-dependent attackers to bypass ForceCommand restrictions and possibly have other unspecified impact via a .. (dot dot) in a (1) LC_*, (2) LANG, or other locale environment variable.

CVE-2014-2226
Published: 2014-07-29
Ubiquiti UniFi Controller before 3.2.1 logs the administrative password hash in syslog messages, which allows man-in-the-middle attackers to obtains sensitive information via unspecified vectors.

CVE-2014-3541
Published: 2014-07-29
The Repositories component in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary code via serialized data associated with an add-on.

CVE-2014-3542
Published: 2014-07-29
mod/lti/service.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) is...

Best of the Web
Dark Reading Radio