Writers of a password-stealing Trojan horse program have found that a little patience can lead to a lot of infections.
They have managed to infect hundreds of thousands of computers -- including more than 14,000 within one unnamed global hotel chain -- by waiting for system administrators to log onto infected PCs and then using a Microsoft administration tool to spread their malicious software throughout the network.
The criminals behind the Coreflood Trojan are using the software to steal banking and brokerage account usernames and passwords. They've amassed a 50G-byte database of this information from the machines they've infected, according to Joe Stewart, director of malware research with security vendor SecureWorks.
"They've been able to spread throughout entire enterprises," he said. "That's something you rarely see these days."
Since Microsoft shipped its Windows XP Service Pack 2 software with its locked-down security features, hackers have had a hard time finding ways to spread malicious software throughout corporate networks. Widespread worm or virus outbreaks soon dropped off after the software's August 2004 release.
But the Coreflood hackers have been successful, thanks in part to a Microsoft program called PsExec, which was written to help system administrators run legitimate software on computers across their networks.
For a widespread infection, attackers must first compromise a system on the network by tricking the user into downloading their program. Then, when a system administrator logs onto that desktop machine -- to perform routine maintenance, for example -- the malicious software tries to run PsExec and install malware on all other systems on the network.
Often the technique succeeds.
Over the past 16 months, Coreflood's authors have infected more than 378,000 computers. SecureWorks has counted thousands of infections in university networks and has found financial companies, hospitals, law firms, and even a U.S. state police agency that have had hundreds of infections. "It's kind of insane how often they are getting on hundreds or thousands of computers at a single company," Stewart said. "They've probably stolen far more accounts than they can use."
The SANS Internet Storm Center reported one of the infections, which affected 600 machines on a 3,000 PC network, on June 25.
Malicious programs have used PsExec for more than five years, said the software's creator, Mark Russinovich, a Microsoft technical fellow. However, this is the first time he had heard of it being used in this fashion. "PsExec doesn't expose anything that a malware author can't code themselves or even accomplish with alternate mechanisms," he said in an e-mail interview. "Once you have credentials that give you local admin rights via remote access, you own that system."
Coreflood, which is also known as the AFcore Trojan, has been around for about six years. It has been used in the past for such things as launching denial-of-service attacks, but not to steal passwords, Stewart said.
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Refresh your AUP: Top tips to ensure your acceptable use policy is fit for purpose
Gaining Competitive Advantage Through Enterprise Planning
Making the Business Case for IT Consolidation
CRM your salespeople will love
Mimosa™ NearPoint™ for Microsoft® Exchange Server: Email Archiving 101
How to improve employee productivity in small and medium businesses
Business Intelligence and Enterprise Performance Management: Trends for Emerging Businesses
The state of Middleware
Zones provide focussed content from Computerworld and leading technology partners.Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
Fortinet November Threatscape Report Shows Calm Before Holiday Storm 2008-12-05 16:00:00+11
Epicor® Cited as an Order Management Solutions Leader by Independent Research Firm 2008-12-05 15:52:00+11
F-Secure: Growth In Internet Crime Calls For Growth In Punishment 2008-12-05 13:00:00+11
International researchers gather in Sydney to preview the clever web 2008-12-05 09:48:00+11
Borderless corporate networks to shift focus to secure content management in Australia in 2009 2008-12-04 16:06:00+11
Everything you need to know about email and web security (but were afraid to ask)
What you don’t know can destroy your business. It’s hard to imagine modern business without the internet but in the last few years it has become fraught with danger. Read on to discover how internet security can give your business a competitive advantage.












