<br />
<b>Deprecated</b>:  Function create_function() is deprecated in <b>/home/hidefide/public_html/blog/wp-content/plugins/wr-pagebuilder/core/core.php</b> on line <b>127</b><br />
{"id":488,"date":"2016-12-09T15:37:48","date_gmt":"2016-12-09T15:37:48","guid":{"rendered":"https:\/\/icaruspressblog.wordpress.com\/?p=488"},"modified":"2019-04-17T11:40:28","modified_gmt":"2019-04-17T11:40:28","slug":"just-in-time-for-the-holidays-cutwail-and-zeus-deliver-holiday-doom","status":"publish","type":"post","link":"https:\/\/hidefideas.com\/blog\/2016\/12\/09\/just-in-time-for-the-holidays-cutwail-and-zeus-deliver-holiday-doom\/","title":{"rendered":"Just in Time for the Holidays, Cutwail and Zeus Deliver Holiday Doom"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"  wp-image-490 alignright\" src=\"http:\/\/hidefideas.com\/blog\/wp-content\/uploads\/2016\/03\/zeus-greek-mythology-687267_1024_768.jpg\" alt=\"Zeus--greek-mythology-687267_1024_768\" width=\"344\" height=\"258\" srcset=\"https:\/\/hidefideas.com\/blog\/wp-content\/uploads\/2016\/03\/zeus-greek-mythology-687267_1024_768.jpg 1024w, https:\/\/hidefideas.com\/blog\/wp-content\/uploads\/2016\/03\/zeus-greek-mythology-687267_1024_768-300x225.jpg 300w, https:\/\/hidefideas.com\/blog\/wp-content\/uploads\/2016\/03\/zeus-greek-mythology-687267_1024_768-768x576.jpg 768w, https:\/\/hidefideas.com\/blog\/wp-content\/uploads\/2016\/03\/zeus-greek-mythology-687267_1024_768-200x150.jpg 200w\" sizes=\"auto, (max-width: 344px) 100vw, 344px\" \/><br \/>\nAs the holiday season looms near, many of you are probably scrambling to get your shopping done. If you\u2019re particularly shrewd and adventurous, then you probably did most of that shopping online. Kudos to you. But when you combine the holidays with the online world, there\u2019s always a danger that there\u2019ll be more than bundled glee under the Christmas tree. &nbsp;Some presents, like socks, were meant to be opened on <!--more-->Christmas day, even if they aren\u2019t that interesting. Some, like <em>Fifty Shades of Grey<\/em>, are best dumped in the trash before they have a chance to rot your mind.<\/p>\n<p>And others should never, ever be opened, lest you open up a serious can of whoop ass on your computer systems. That\u2019s the warning we all need to heed this year, as a new spam campaign is being delivered by the notorious and pervasive Cutwail botnet. <a href=\"http:\/\/searchsecurity.techtarget.com\/news\/2240173918\/Cutwail-botnet-spam-campaign-tied-to-Zeus-banking-Trojan\">Several sources<\/a> reported this week that the folks at Dell SecureWorks Counter Threat Unit have discovered a nasty little package delivered by Cutwail to inboxes everywhere, and it carries with it a nasty little elf better known as the Gameover Zeus banking Trojan.<\/p>\n<p>\u201cThe spam message is made to look like it comes from many of the top U.S. banks. It reads: \u201cYou have received a new encrypted message or a secure message from [XYZ] Bank.&#8221;&nbsp;The spam message encourages recipients to download an attachment and register for a new system designed to protect privacy and personal information. Instead the attachment contains the Pony downloader, which installs the banking malware,\u201d SearchSecurity reports.<\/p>\n<p>Elizabeth W. Clarke, a Dell SecureWorks spokesperson, told SearchSecurity that \u201cthe Cutwail botnet only needs to employ approximately 10,000 bots per spam campaign to send out hundreds of millions of malicious spam messages to computer users all over the world.&#8221; Santa Claus it\u2019s not, but it\u2019s more than enough to deliver holiday misery to unsuspecting users across the world this holiday season.<\/p>\n<p>The Gameover Zeus botnet is one of the largest around with more than 678,000 infections. But it\u2019s not your father\u2019s botnet. Rather than utilizing the standard command and control (C&amp;C) server paradigm, Zeus is a peer-to-peer botnet. Dell SecureWorks <a href=\"http:\/\/www.secureworks.com\/cyber-threat-intelligence\/threats\/The_Lifecycle_of_Peer_to_Peer_Gameover_ZeuS\/\">points out<\/a> that Gameover is very troubling, because that peer-to-peer design makes taking it down a virtual impossibility. And because it\u2019s privately operated, variants aren\u2019t available on criminal hacking forums. Without the ability to pick up a variant, researchers, security firms, and law enforcement officials can\u2019t get their hands on the Trojan to reverse engineer it.<\/p>\n<p>The pesky little thing, in fact, has been \u201cdetected on corporate systems and systems at universities, defense contractors and government agencies,\u201d SearchSecurity reports. Researchers have apparently detected multiple variants of the email spam, with the common theme of encouraging users to open the attached file, listen to a voicemail message, or register for a new privacy system. Dell SecureWorks has some good, if not obvious, advice, though: train your workers to never, ever open an email attachment or click a link, even if they recognize the sender of the email. Clark cautions \u201cAlways verify that the sender sent the email. Additionally, update your IPS\/IDS countermeasures and firewalls to detect the latest threats.\u201d<\/p>\n<p>According to <a href=\"http:\/\/threatpost.com\/en_us\/blogs\/gameover-zeus-variant-sends-malicious-email-cutwail-botnet-120512\">Kaspersky ThreatPost<\/a>, \u201ca Dell SecureWorks spokesperson stated that as a point a policy Dell does not name victims involved in scams but said they are top U.S. banks.\u201d<\/p>\n<p>SearchSecurity notes that the <a href=\"http:\/\/searchsecurity.techtarget.com\/definition\/Zeus-Trojan-Zbot\">Zeus Trojan<\/a> has presented a major headache for banks and other financial firms, \u201cwith different variants infecting customer systems attempting to dupe individuals into giving up their account credentials.&nbsp;<a href=\"http:\/\/searchsecurity.techtarget.com\/news\/1524617\/New-variant-of-the-Zeus-Trojan-spotted-by-Trend-Micro\">New variants of Zeus<\/a>&nbsp;are frequently detected by researchers. The issue has become such a problem that Microsoft took legal action to&nbsp;<a href=\"http:\/\/searchfinancialsecurity.techtarget.com\/news\/2240147481\/Microsoft-attempts-legal-action-to-disrupt-some-Zeus-botnets\">disrupt some Zeus botnets<\/a>. But despite a few victories, cybercriminals continue to recover their operations.\u201d<\/p>\n<p>But just in time for Christmas, it gets worse. The criminals behind the Gameover Zeus botnet are considered to be the most devious and aggressive, apparently implementing a system that\u2019s elaborate and smacking of organized crime. They recruit money mules to drain US and European bank accounts and employ a number of nasty tools, like the automated features of the <a href=\"http:\/\/www.scmagazine.com\/hackers-add-java-exploit-to-blackhole-toolkit\/article\/249508\/\">BlackHole<\/a> Exploit toolkit, and <a href=\"http:\/\/ddos.arbornetworks.com\/2012\/05\/dirt-jumper-ddos-bot-increasingly-popular\/\">DirtJumper<\/a>, which is being used to deliver distributed denial of service (DDoS) attacks on financial institutions while bank accounts are being emptied.<\/p>\n<p>As the holidays near, most of us hope for a little quiet time with family, a lot of holiday cheer and good food, and hopefully, a little global peace. What we don\u2019t hope for is total financial ruin and the disasters associated with this lump of coal-inspired atrocity. Keep safe this holiday season and leave some packages unopened.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As the holiday season looms near, many of you are probably scrambling to get your shopping done. If you\u2019re particularly shrewd and adventurous, then you&hellip; <\/p>\n","protected":false},"author":3,"featured_media":490,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13,14],"tags":[11,9,10,8,7],"class_list":["post-488","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","category-spam","tag-allspammedup","tag-bot","tag-botnet","tag-malware","tag-spam","jsn-master"],"_links":{"self":[{"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/posts\/488","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/comments?post=488"}],"version-history":[{"count":2,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/posts\/488\/revisions"}],"predecessor-version":[{"id":1777,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/posts\/488\/revisions\/1777"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/media\/490"}],"wp:attachment":[{"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/media?parent=488"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/categories?post=488"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/tags?post=488"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}