Spyware ID Theft Ring !!

GEC: Discuss gaming, computers and electronics and venture into the bizarre world of STGODs.

Moderator: Thanas

Post Reply
User avatar
theski
Sith Marauder
Posts: 4327
Joined: 2003-01-28 03:20pm
Location: Hurricane Watching

Spyware ID Theft Ring !!

Post by theski »

Fuckers, they should be tied to a Fire ant hill for this shit... :evil:
Spyware Researchers Discover ID Theft Ring
Spyware researchers picking apart one of the more notorious spyware programs have stumbled upon what appears to be a massive identity theft ring hijacking confidential data from millions of infected computers.

Sunbelt Software Inc., makers of the enterprise-grade CounterSpy spyware protection product, made the discovery during an audit of "CoolWebSearch," a program that routinely hijacks Web searchers, browser home pages and other Internet Explorer settings.

During the research, Sunbelt researcher Patrick Jordan deliberately installed the "CoolWebSearch application on a machine and immediately noticed that the infected system became a spam zombie that was placing callbacks to a remote server.

When Jordan visited the remote server, he was shocked to find that it was being used to distribute sensitive personal information from millions of PC users infected by the spyware application.


"We found the keylogger transcript files that are being uploaded to the servers. We're talking real spyware stuff…chat sessions, usernames, passwords, bank account information, full names, addresses," said Sunbelt president Alex Eckelberry.

Read more here about the many faces of spyware.

In an interview with Ziff Davis Internet News, Eckelberry said the sophistication of the operation suggests it's the work of a "massive identity theft ring" that used keystroke loggers to grab confidential information that could be used to create fake online identities.

"I'm not being dramatic. This is the most repulsive thing I've ever seen. It's very painful to see what's in these log files that are being uploaded in real time. We're seeing a lot of bank information and usernames and passwords to get in," Eckelberry said.

He said the log files included logins to one business bank account with more than $350,000 and another small company in California with over $11,000, readily accessible.


"There are lots of eBay account information and names and addresses of the people owning those accounts. Names, passwords, all matched up," Eckelberry added.

Read more here about Sunbelt's acquisition of a Google-like spyware sniffer.

He said the server, which is hosted out of a data center in Texas, was effectively a "massive repository of stolen data" that was being replenished in real time.

"As the [log] file gets to a certain size, it gets taken down and a new file starts generating. This goes on nonstop. We've been watching it for a few days while trying to get to the FBI, and it just keeps growing and growing."

While the site is being hosted in the United States, Eckelberry said the domain name is registered to an offshore company.

Eckelberry said the huge size of the log files is a clear indication that thousands of machines are pinging back daily.

In some cases, where users appeared to be at immediate risk of losing a considerable amount of money, Sunbelt has contacted the affected individuals.

Eckelberry said the "CoolWebSearch" payload included a typical adware download that immediately scanned the infected machine for e-mails to use for spam runs. It then sets up a "very intelligent keylogger" that looks for very specific information.

"This won't get caught by a typical anti-spyware application," he said, noting that the keystroke logger was able to pick up identity-related data for delivery to the remote server.

SPYWARE
Sudden power is apt to be insolent, sudden liberty saucy; that behaves best which has grown gradually.
Tiger Ace
Jedi Knight
Posts: 627
Joined: 2005-04-07 02:03am
Location: AWAY

Post by Tiger Ace »

Maybe this will get CWS shut down.
Useless geek posting above.

Its Ace Pace.
User avatar
Dakarne
Village Idiot
Posts: 948
Joined: 2005-08-01 08:10am
Location: Somewhere in Britain
Contact:

Post by Dakarne »

They should be put in a room with Einy...
User avatar
Einhander Sn0m4n
Insane Railgunner
Posts: 18630
Joined: 2002-10-01 05:51am
Location: Louisiana... or Dagobah. You know, where Yoda lives.

Post by Einhander Sn0m4n »

Dakarne wrote:They should be put in a room with Einy...
How'd you know I'd like nothing more than to shoot the CWS fuckheads in the kneecaps with a .458 SOCOM AR15? :lol:

Seriously, I've had to deal with CWS at Spywareinfo, and they've shown themselves to be bound by no law enacted by man. Hacks, DDoS attacks, DNS poisoning, and of course their ever-changing super-hella damn-near impossible-to-remove TROJANware can attest to that. I wouldn't be surprised if they solicit for murder or have ties with the blood-diamond vendors in Africa. They're terrorists, pure and simple.
Image Image
User avatar
Chmee
Sith Marauder
Posts: 4449
Joined: 2004-12-23 03:29pm
Location: Seattle - we already buried Hendrix ... Kurt who?

Post by Chmee »

What was it Jayne said: "I'm not going to kill him ... well, not right away ..." ?

They're scum all right .... and yet scum like this are what pay Chmee's rent. We do a little anti-spyware in our gateway IPS on corporate firewalls now, we'll probably expand through partnership into desktop anti-spyware/IPS next year. There's never a shortage of assholes to provide free advertising for corporate network security vendors .....
[img=right]http://www.tallguyz.com/imagelib/chmeesig.jpg[/img]My guess might be excellent or it might be crummy, but
Mrs. Spade didn't raise any children dippy enough to
make guesses in front of a district attorney,
an assistant district attorney, and a stenographer
.

Sam Spade, "The Maltese Falcon"

Operation Freedom Fry
User avatar
LapsedPacifist
Jedi Knight
Posts: 608
Joined: 2004-01-30 12:06pm
Location: WestCoast N. America

Post by LapsedPacifist »

I'm gearing up for supporting a bunch of 1Ls as school starts, and I want as much anti-spyware firepower as I can possibly get. I saw a LOT of CWS last year.

LP
Ogrek is beyond strategy.

<- Avatar from Dr. Roy's List of Stomatopods for the Aquarium
Post Reply