Re: Spyware ID Theft Ring...

JerseyCurl

Cathlete
Spyware Researchers Discover ID Theft Ring Ryan Naraine - eWEEK
Mon Aug 8,10:43 AM ET



Spyware researchers picking apart one of the more notorious spyware programs have stumbled upon what appears to be a massive identity theft ring hijacking confidential data from millions of infected computers.

Sunbelt Software Inc., makers of the enterprise-grade CounterSpy spyware protection product, made the discovery during an audit of "CoolWebSearch," a program that routinely hijacks Web searchers, browser home pages and other Internet Explorer settings.


During the research, Sunbelt researcher Patrick Jordan deliberately installed the "CoolWebSearch application on a machine and immediately noticed that the infected system became a spam zombie that was placing callbacks to a remote server.


When Jordan visited the remote server, he was shocked to find that it was being used to distribute sensitive personal information from millions of PC users infected by the spyware application.


"We found the keylogger transcript files that are being uploaded to the servers. We're talking real spyware stuff…chat sessions, usernames, passwords, bank account information, full names, addresses," said Sunbelt president Alex Eckelberry.


In an interview with Ziff Davis Internet News, Eckelberry said the sophistication of the operation suggests it's the work of a "massive identity theft ring" that used keystroke loggers to grab confidential information that could be used to create fake online identities.


"I'm not being dramatic. This is the most repulsive thing I've ever seen. It's very painful to see what's in these log files that are being uploaded in real time. We're seeing a lot of bank information and usernames and passwords to get in," Eckelberry said.


He said the log files included logins to one business bank account with more than $350,000 and another small company in California with over $11,000, readily accessible.


"There are lots of eBay account information and names and addresses of the people owning those accounts. Names, passwords, all matched up," Eckelberry added.


He said the server, which is hosted out of a data center in Texas, was effectively a "massive repository of stolen data" that was being replenished in real time.

"As the [log] file gets to a certain size, it gets taken down and a new file starts generating. This goes on nonstop. We've been watching it for a few days while trying to get to the FBI, and it just keeps growing and growing."


While the site is being hosted in the United States, Eckelberry said the domain name is registered to an offshore company.


Eckelberry said the huge size of the log files is a clear indication that thousands of machines are pinging back daily.




In some cases, where users appeared to be at immediate risk of losing a considerable amount of money, Sunbelt has contacted the affected individuals.


Eckelberry said the "CoolWebSearch" payload included a typical adware download that immediately scanned the infected machine for e-mails to use for spam runs. It then sets up a "very intelligent keylogger" that looks for very specific information.

"This won't get caught by a typical anti-spyware application," he said, noting that the keystroke logger was able to pick up identity-related data for delivery to the remote server.

Check out eWEEK.com's Security Center for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzer's Weblog.
 
I know when I first heard this it freaked me out to think that someone could do that and you would not even know it. It's no wonder why Identity Theft is one of the highest growing crimes.
 
Actually, it's one of the reasons I do use Online Banking. I can very easily check my account balance to make sure that nothing odd is going on.

Just buying something on line like a Cathe DVD can open you up to things like this - one of the reasons to have an anti-spyware program on your computer. I use Ad-aware and Spybot (both are Freeware). There are others out there but make sure they have a website where you can get updates frequently. As soon as spyware blocks a hacker, the hacker figures out a way around it.
 
My computer actually got nailed by "coolwebsearch" in spite of Norton Antivirus running. All spyware programs (adaware, spybot search and destroy, and Yahoos) saw it but couldn't remove it. It was pretty nasty. I had to reformat the hardrive and rebuild my system.

I do a lot of credit card business online we always watch our accounts.

As far as your privacy, a lot of people bank on their computer without realizing it. How many of you are using Quicken or Money to run your accounts even if you aren't doing online banking?

With all of these virus proliferations I always come back to the idea that Microsoft needs to be held accountable for their weak security. Why doesn't Linux or the web browser options of Opera or Firefox seem to have the problems that the Microsoft systems do? With what people pay for "geniune Microsoft" there should be real security not an update 2 months after you get nailed.
 

Our Newsletter

Get awesome content delivered straight to your inbox.

Top