Accurate, Focused Research on Law, Technology and Knowledge Discovery Since 2002

NetWitness Discovers Massive ZeuS Compromise

News release: “NetWitness, the world leader in advanced persistent threat detection and real-time network forensics, announced today that its analysts have discovered a dangerous new ZeuS botnet affecting 75,000 systems in 2,500 organizations around the world. The newly-discovered infestation, dubbed the “Kneber botnet” after the username linking the infected systems worldwide, gathers login credentials to online financial systems, social networking sites and email systems from infested computers and reports the information to miscreants who can use it to break into accounts, steal corporate and government information, and replicate personal, online and financial identities. NetWitness first discovered the Kneber botnet in January during a routine deployment of the NetWitness advanced monitoring solutions. Deeper investigation revealed an extensive compromise of commercial and government systems that included 68,000 corporate login credentials, access to email systems, online banking sites, Facebook, Yahoo, Hotmail and other social networking credentials, 2,000 SSL certificate files, and dossier-level data sets on individuals including complete dumps of entire identities from victim machines.”

  • The “Kneber” BotNet – A ZeuS Discovery and Analysis: At its core, ZeuS is a botnet system designed to steal information from an infected host. Unlike a traditional keylogger system, which records every keystroke, ZeuS can specifically target information desired by the criminal miscreant.”
  • Sorry, comments are closed for this post.