A new Zeus botnet has been discovered affecting 75,000 systems in 2,500 organizations around the world. Both corporate and government networks have become victims of the severe cyberattack dubbed the Kneber attack, named after the username linked with the attack.
The attack was first discovered in January while a security analyst at Hernon, Va.-based NetWitness was installing a monitoring system for a client. In investigating the discovery, the company found Kneber had compromised 68,000 corporate log-ins; access to various e-mail systems, including Yahoo and Hotmail; access to online banking sites; and access to social-networking sites, including Facebook. All of this was done in a four-week period.
Kneber has been identified as a botnet, where compromised computers run software remotely.
“Systems compromised by this botnet provide the attackers not only user credentials and confidential information, but remote access inside the compromised networks,” said Amit Yoran, CEO of NetWitness and former director of the National Cyber Security Division.
The Kneber botnet is not stopped by traditional malware protection or other intrusion-detection systems, and NetWitness analysts fear organizations will not see the damage from this attack until it has already occurred.
More than half the infected machines were also infected with a peer-to-peer botnet dubbed Waledac, a worm that is capable of collecting and forwarding password information. It’s also capable of receiving commands from a remote server, including to upgrade malware components or send information from the infected computer.
Used together, the botnets have the potential to enable hackers to collaborate in what NetWitness said may be a “criminal underground.”
“On a microlevel, there are new versions of Trojans and viruses that come out all the time and some gain traction while others do not,” said Matthew Prince, cocreator of Project Honey Pot, a spam tracking network. “On the macrolevel it is really scary.”
The…