首页 | 编程语言 | 网站建设 | 游戏天堂 | 冲浪宝典 | 网络安全 | 操作系统 | 软件时空 | 硬件指南 | 病毒相关 | IT 认证
软讯网络 > 软件时空 > 软件相关 > Russian (Gozi) Trojan powering massive ID-theft ring
【标  题】:Russian (Gozi) Trojan powering massive ID-theft ring
【关键字】:Russian,Gozi,Trojan,powering,massive,ID-theft,ring
【来  源】:http://blog.csdn.net/iiprogram/archive/2007/04/16/1566175.aspx

Russian (Gozi) Trojan powering massive ID-theft ring

Researchers at SecureWorks have stumbled upon what appears to be a massive identity theft ring using state-of-the-art Trojan code to steal confidential data from thousands of infected machines in the U.S.

The Trojan, which connects to a server in Russia, has so far pilfered information from more than 5,200 home computers with 10,000 account records. The records retrieved included account numbers and passwords from clients of many of the top global banks and financial services companies (over 30 banks and credit unions were represented), the top US retailers, and the leading online retailers.

"The stolen data also contained numerous user accounts and passwords for employees working for federal, state and local government agencies, as well national and local law enforcement agencies. The stolen data also contained patient medical information, via healthcare employees and healthcare patients, whose username and passwords had been compromised via their home PC," Jackson said.

In a fascinating blow-by-blow description posted online, SecureWorks researcher Don Jackson explained how he reverse-engineered the Trojan (named Gozi) and traced it back to a Russian mothership server that contained information and employee login information for confidential government and law enforcement applications.

This data was being offered for sale by Russian Hackers for an amount totaling over $2 million. The subscription service hawking the stolen information has been disabled but, as of today, the server hosting the data is still receiving stolen data.

  • Steals SSL data using advanced Winsock2 functionality
  • Users state-of-the-art, modularized trojan code
  • Launch attacks through Internet Explorer browser exploits
  • Users customized server/database code to collect sensitive data
  • Offers a customer interface for online purchases of stolen data
  • Steals data primarily from infected home PCs
  • Accounts at top financial, retail, health care, and government services affected
  • The black market value of the stolen data is at least $2 million 

Even more worrying, Jackson found that the Trojan went undetected for several weeks (and, in some cases, months) by many anti-virus vendors. He also warned that there are two other known Gozi variants making the rounds, which suggests this isn't the last we've heard of Gozi.

As of the publication date, the server used by the Gozi trojan is still up. The server status is as follows:

  • Still processing data from existing trojan infections
  • Still allowing new infections to "register" themselves
  • Still accepting and processing stolen data from new infections
  • The large cache of stolen data has been removed
  • The admin interface used to add subscriptions has been removed
  • The customer interface used to buy stolen data has been removed
  • The server is no longer hosting any executables  

(See Jackson's description of the identity-theft operation connected to the Gozi Trojan). 

“黑客”入侵马英九工作室 广发病毒信恶意搞破坏:【上一篇】
blob分析:【下一篇】
【相关文章】
  • java中String的操作api
  • Spring学习笔记1
  • 我们如何学习Spring 2.0
  • JSF+Hibernate+Spring学习
  • Domino技术-Domino Domain Monitoring (DDM) -DDM介绍
  • hibernate+spring的一个简单分页实现
  • 一个关于spring+hibernate的例子
  • 用 Spring MVC 轻松进行应用程序开发
  • Spring总结
  • java string 中的split方法
  • 【随机文章】
  • 晶振电路的原理
  • 著名黑客组织--大屠杀2600
  • 用SQL Server为Web浏览器提供图像1
  • 谈谈软件项目管理的重要性目录
  • 操作系统日常检查命令
  • FLASH Action实战系列四
  • UNIX环境高级编程(第二版) 读书代码(1-5)
  • [全程建模]几个建模问题的回答
  • 多线程的网络程序实现
  • 今天去笔试,通过了
  • 【相关评论】
    没有相关评论
    【发表评论】
    姓名:
    邮件:
    随机码*
    评论*
          
    |  首 页  |  版权声明  |  联系我们   |  网站地图  |
    CopyRight © 2004-2007 软讯网络 All Rigths Reserved.