Vulnerabilities / Threats
01:46 PM

Waledac Botnet Contains Almost 490,000 Stolen Email Passwords

With numerous real-world credentials built-in, the worm can bypass many spam and security defenses, find security researchers.

Security researchers have cracked the code for version 2 of the Waledac worm, used by attackers to build botnets, and found that it carries numerous credentials that enable it to bypass spam filters and security defenses.

"We found that the botmasters have a tremendous amount of stolen credentials," blogged Brett Stone-Gross, a developer and threat analyst at LastLine, a cybercrime intelligence and network monitoring firm.

For starters, the most recent version of Waledac -- the successor to the Storm worm -- contains 123,920 login credentials for FTP servers, through which Waledac's botmasters -- or rather, their automated attack toolkits, issue instructions to worm-infected (aka zombie) PCs.

Oftentimes, these instructions involve rerouting the browsers of infected machines to Web sites that serve malware or advertisements for discount pharmaceuticals. In January alone, LastLine saw the worm redirecting to nearly 10,000 compromised or malicious Web pages across 222 Web sites.

LastLine also discovered that Waledac contains 489,528 credentials for POP3 email accounts. "These credentials are known to be used for 'high-quality' spam campaigns," Stone-Gross said. "The technique abuses legitimate mail servers by authenticating as the victim through the SMTP-AUTH protocol to send spam messages. This method makes IP-based blacklist filtering considerably more difficult."

In December 2010, the previous version of Waledac went dark for about a week. After its hiatus, the updated version appeared, containing not only the built-in credentials, but also enhanced command-and-control capabilities, including improvements in the proprietary Ad Hoc Network Management Protocol (ANMP) the worm uses to communicate with a "bootstrap server" that issues its instructions.

Although Waledac has been relatively quiet recently, the worm still has cybercrime potential to spare. "The Waledac botnet remains just a shadow of its former self for now, but that's likely to change given the number of compromised accounts that the Waledac crew possesses," said Stone-Gross. As of January 2011, LastLine said that the Waledac botnet appeared to comprise about 12,000 infected machines.

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Current Issue
Five Emerging Security Threats - And What You Can Learn From Them
At Black Hat USA, researchers unveiled some nasty vulnerabilities. Is your organization ready?
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio
According to industry estimates, about a million new IT security jobs will be created in the next two years but there aren't enough skilled professionals to fill them. On top of that, there isn't necessarily a clear path to a career in security. Dark Reading Executive Editor Kelly Jackson Higgins hosts guests Carson Sweet, co-founder and CTO of CloudPassage, which published a shocking study of the security gap in top US undergrad computer science programs, and Rodney Petersen, head of NIST's new National Initiative for Cybersecurity Education.