Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Russian Gang Hijacking PCs in Vast Scheme
The New York Times ^ | August 5, 2008 | John Markoff

Posted on 08/06/2008 12:00:14 PM PDT by Perseverando

A criminal gang is using software tools normally reserved for computer network administrators to infect thousands of PCs in corporate and government networks with programs that steal passwords and other information, a security researcher has found.

The new form of attack indicates that little progress has been made in defusing the threat of botnets, networks of infected computers that criminals use to send spam, steal passwords and do other forms of damage, according to computer security investigators.

Several security experts say that although attacks against network administrators are not new, the systematic use of administrative software to spread malicious software has not been widely seen until now.

The gang was identified publicly in May by Joe Stewart, director of malware research at SecureWorks, a computer security firm in Atlanta. Mr. Stewart, who has determined that the gang is based in Russia, was able to locate a central program controlling as many as 100,000 infected computers across the Internet. The program was running at a commercial Internet hosting computer center in Wisconsin.

Mr. Stewart alerted a federal law enforcement agency that he declined to identify, and he said that it was investigating the matter. Although the original command program was shut down, the gang immediately reconstituted the system, he said, moving the control program to another computer in the Ukraine, beyond the reach of law enforcement in the United States.

The system infects PCs with a program known as Coreflood that records keystrokes and steals other information. The network of infected computers collected as much as 500 gigabytes of data in a little more than a year and sent it back to the Wisconsin computer center, Mr. Stewart said.

One of the unique aspects of the malicious software is that it captures screen information in addition to

(Excerpt) Read more at nytimes.com ...


TOPICS: Business/Economy; Crime/Corruption; Foreign Affairs; News/Current Events
KEYWORDS: botnets; bots; computer; coreflood; hacker; hacking; internet; internetsecurity; microsoft; passwords; software; spam; tech; virus

1 posted on 08/06/2008 12:00:17 PM PDT by Perseverando
[ Post Reply | Private Reply | View Replies]

To: Perseverando; All
has determined that the gang is based in Russia

They're probably part of Putin's "gang". The ChiComs have been doing the same thing: attacking U.S. government computers.

2 posted on 08/06/2008 12:07:56 PM PDT by ETL (Lots of REAL smoking-gun evidence on the demonRats at my Home page: http://www.freerepublic.com/~etl)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Perseverando

Another reason not to use your credit card over the internet. The flaw in the internet business model.


3 posted on 08/06/2008 12:08:35 PM PDT by StormEye
[ Post Reply | Private Reply | To 1 | View Replies]

To: ETL

By the way, I ran across the article on Drudge today.

Will be unable to post further today. Freep on!


4 posted on 08/06/2008 12:12:19 PM PDT by Perseverando
[ Post Reply | Private Reply | To 2 | View Replies]

To: Perseverando

What article?


5 posted on 08/06/2008 12:13:41 PM PDT by ETL (Lots of REAL smoking-gun evidence on the demonRats at my Home page: http://www.freerepublic.com/~etl)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Perseverando

Waht happen to the good ‘ol days when gangs dealt in drugs and whores?


6 posted on 08/06/2008 12:26:35 PM PDT by wolfcreek (I see miles and miles of Texas....let's keep it that way.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Perseverando
Symantec has been wathcing this for some time.
For more details "Click Here"
7 posted on 08/06/2008 12:35:54 PM PDT by An Old Man ("The limits of tyrants are prescribed by the endurance of those whom they suppress." Douglas)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Perseverando

I got news for ya - nothing new and not only Russian -

I understand one way for protection is to copy/paste your passwords rather than keystrokes/


8 posted on 08/06/2008 12:55:56 PM PDT by maine-iac7 (No trees were killed in sending this message but a large number of electrons were terribly agitated)
[ Post Reply | Private Reply | To 1 | View Replies]

To: maine-iac7

IPC can be hijacked just as easy...


9 posted on 08/06/2008 1:00:59 PM PDT by Michael Barnes (You will know I am dead when a news paper reoprts "The Government has Michael Barnes' guns".)
[ Post Reply | Private Reply | To 8 | View Replies]

To: StormEye
Another reason not to use your credit card over the internet. The flaw in the internet business model.

The problem isn't the Internet.

The problem is that Windows machines (and every one of the members of the bot nets is a Windows machine) are inherently buggy and prone to malware like this.

All software has flaws. Windows has so many that an entire criminal industry has sprung up around the existence of so many flaws.

10 posted on 08/06/2008 1:06:29 PM PDT by Knitebane (Happily Microsoft free since 1999.)
[ Post Reply | Private Reply | To 3 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson