Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Bank data-stealing Trojan infects hundreds of thousands of PCs - researcher
Finextra ^ | July 30, 2009 | Finextra

Posted on 07/31/2009 9:36:51 AM PDT by the invisib1e hand

A "tremendous" amount of financial data has been stolen by a Trojan that has infected hundreds of thousands of corporate and personal PCs, according to information security specialist SecureWorks.

Clampi, also known as Ligats, Ilomo or Rscan, has spread across Microsoft networks in a "worm-like fashion" and is "one of the largest and most professional thieving operations on the Internet" says Joe Stewart, director of malware research at SecureWorks' counter threat unit.

Once it has infected a PC, the Trojan monitors Web sessions to see if one of 4500 targeted sites are visited. If a victim uses one of these sites - which include those of banks, credit card companies, stock brokerages and insurance firms - it captures sensitive information such as usernames, passwords and PINs.

Stewart claims to have so far identified 1400 affected sites in 70 different countries.

Stewart says Clampi is operated by a "serious and sophisticated" organised crime group from Eastern Europe and has been implicated in numerous high-dollar thefts from banking institutions.

Its recent success in infecting victims has been achieved by using domain administrator credentials - either stolen by the Trojan or re-used, or by virtue of the fact that a domain administrator has logged into an already infected system.

Once domain administrator privileges are granted, the Trojan uses the SysInternals tool "psexec" to copy itself to all computers on the domain. In addition, it serves as a proxy server used by criminals to cloak their activity when logging into stolen accounts.


TOPICS: Business/Economy; Crime/Corruption; Culture/Society; Technical
KEYWORDS: bank; finance; trojan; worm

1 posted on 07/31/2009 9:36:51 AM PDT by the invisib1e hand
[ Post Reply | Private Reply | View Replies]

To: ShadowAce

Ping


2 posted on 07/31/2009 9:43:43 AM PDT by Born Conservative (Working hard so those on public assistance don't have to.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: the invisib1e hand

Where’s the Computer Czar?

Obama’s fault.


3 posted on 07/31/2009 9:45:42 AM PDT by don-o (My son, Ben - Marine PFC- 1/16/09 - Parris Island - LC -6/4/09 - 29 Palms - Camp Pendleton 6/18)
[ Post Reply | Private Reply | To 1 | View Replies]

To: the invisib1e hand

any scans out there to find these??


4 posted on 07/31/2009 9:52:33 AM PDT by elpadre (AfganistaMr Obama said the goal was to "disrupt, dismantle and defeat al-Qaeda" and its allies.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: the invisib1e hand

any scans out there to find these??


5 posted on 07/31/2009 9:53:02 AM PDT by elpadre (AfganistaMr Obama said the goal was to "disrupt, dismantle and defeat al-Qaeda" and its allies.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: the invisib1e hand

hmmm... the IT people at the bank where my spouse is employed just pushed out an emergency security patch to both their local and remote users


6 posted on 07/31/2009 9:58:53 AM PDT by TheRightGuy (I want MY BAILOUT ... a billion or two should do!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: elpadre

Idunno. I’d go hunting on the site of the security company featured in the article, or google it up.


7 posted on 07/31/2009 9:59:14 AM PDT by the invisib1e hand (The revolution IS being televised.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: rdb3; Calvinist_Dark_Lord; GodGunsandGuts; CyberCowboy777; Salo; Bobsat; JosephW; ...

8 posted on 07/31/2009 11:36:18 AM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: the invisib1e hand

I bank online, but not in Windows. Neither do I key in my account names and passwords.


9 posted on 07/31/2009 12:32:18 PM PDT by Clara Lou (Spread my work ethic, not my wealth.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: the invisib1e hand
Virus bump.
10 posted on 07/31/2009 3:49:25 PM PDT by SuperLuminal (Where is another agitator for republicanism like Sam Adams when we need him?)
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson