Anonymous Allies Hit With Zeus Malware

  /     /     /  
Publicated : 22/11/2024   Category : security


Anonymous Allies Hit With Zeus Malware


Fraudsters steal hacktivist supporters banking, webmail logins by modifying Anonymous attack tool with a hidden Trojan.



Anonymous: 10 Facts About The Hacktivist Group (click image for larger view and for slideshow)
Would-be Anonymous supporters, choose your attack tools carefully. Thats because fraudsters have been disguising a banking Trojan application in a tool used by Anonymous for launching
distributed denial-of-service
(DDoS) attacks.
Anonymous supporters have been deceived into installing Zeus botnet clients purportedly for the purpose of DoS attacks. The Zeus client does perform DoS attacks, but it doesnt stop there. It also steals the users online banking credentials, webmail credentials, and cookies, according to a
Symantec Security Response blog
posted Sunday.
Symantec said it had traced related attacks back to January 20, 2012, which is the day that the
FBI took down Megaupload
. An attacker took a popular PasteBin guide, used by Anonymous members for downloading and using the DoS tool Slowloris, and modified it, said Symantec. As of February 15, 2012, Symantec said that 470 Tweets still linked to the Pastebin post with the malicious link.
[ Hacktivism and fraud have increased security threats. Learn
10 Lessons From RSA Security Conference
. ]
According to a
site devoted to Slowloris
, the DDoS tool holds connections open by sending partial HTTP requests. But the Pastebin post--the original dates from May 2011--was modified to include a link to a Trojanized version of Slowloris. When the Trojanized Slowloris tool is downloaded and executed by an Anonymous supporter, a Zeus (also known as Zbot) botnet client is installed, said Symantec. After installation of the Zeus botnet client, the malware dropper attempts to conceal the infection by replacing itself with the real Slowloris DoS tool.
Zeus malware
is designed to steal peoples sensitive financial information, but is also often used by attackers to surreptitiously turn infected PCs--aka zombies--into nodes in a
botnet
. In other words, Anonymous attackers who download the malicious version of Slowloris could find their PCs participating in a DDoS attack, just not of their own choosing.
Thats in addition to this
implementation of Zeus
being used, said Symantec, to transmit cookies, online banking credentials, and webmail credentials from an infected PC to the botnet owners command-and-control server.
While Anonymous has generally expressed antagonism toward security firms--the hacktivist collective did create a spin-off dubbed
AntiSec
, after all--
The Register
spotted
at least one pro-Anonymous Twitter channel picking up on Symantecs Slowloris malware warning, in a post that read, Anonymous supporters tricked into installing Zeus trojan. This MUSTNT happen. Be careful what you post and click on!
This isnt the first warning related to the tools offered for participating in Anonymous DDoS campaigns. Last year, for example,
LulzSec leader Sabu
labeled the groups low orbit ion canon DDoS tool as a joke. Whats curious with the malicious version of Slowloris discovered by Symantec, however, is that beyond stealing the financial details of whoever installs it, the software also still attacks websites targeted by Anonymous.
Security professionals often view compliance as a burden, but it doesnt have to be that way. In this report, we show the security team how to partner with the compliance pros.
Download the report here
. (Free registration required.)

Last News

▸ ArcSight prepares for future at user conference post HP acquisition. ◂
Discovered: 07/01/2025
Category: security

▸ Samsung Epic 4G: First To Use Media Hub ◂
Discovered: 07/01/2025
Category: security

▸ Many third-party software fails security tests ◂
Discovered: 07/01/2025
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Anonymous Allies Hit With Zeus Malware