Full Coverage

Malicious server used to propagate Zbot shut down

Jul 2, 2009
 
Story Timeline:  147 days

A criminal operation has been halted by the shutdown of a malicious server in the Cayman Islands, but the attackers are likely to be looking for a new home. Prevx researchers recently discovered a site where the trojan Zbot had uploaded the FTP login credentials from more than 68,000 websites, including companies such as Bank of America, BBC, and Symantec. Since then, more than 20,000 additional stolen FTP credentials were used to inject malicious scripts on those sites, Jacques Erasmus, director of research at Prevx, told SCMagazineUS.com. But the attacker's server, based in the Cayman Islands, was shut down on earlier this week. Up until last week, when visiting a compromised website, users were being infected (by means of a drive-by download) with Zbot, a trojan that captures keystrokes to obtains login credentials and... [read full story]                    

powered by
Add Comment
Latest article on this story:

News: Malicious server used to propagate Zbot shut down

scmagazine.com.au Jul 2, 2009
First article on this story:

News: Malicious server used to propagate Zbot shut down

scmagazine.com.au Jul 2, 2009
Selected publications with coverage of this story:
RELATED