
Hackers affect ordinary people, corporations, and governments. This post is presented to inform the internet community about the latest threat to free traffic and commerce. Recommendations to protect yourself are listed below the story.
Spam attached to this blog until a simple captcha was added. Also, a defensve plug-in proved to be offensive when it denied access. Noting its Russian origin, when I went to the library in order to log-in, I deleted the Trojan plug-in.
SpyEye hacker toolkit to lead to surge in cyberattacks
By Byron Acohido, USA TODAY
The odds that a cybergang will stealthily turn your PC into a bot this summer and use it to carry out all manner of cyberattacks just notched notably higher.
That’s the upshot of a premier hacker’s toolkit, called SpyEye, recently being made accessible to cybercriminals of all stripes.
Security analysts anticipate a surge in SpyEye attacks the rest of this year. “Every level of criminal, from the lowest to the highest rungs, can now use one of the deadliest Swiss Army knife hacking toolkits in the world,” say Sean Bodmer, senior threat intelligence analyst at network security firm Damballa.
It’s been about a week since the keys to accessing SpyEye were publicly disclosed. So far 14 cyber-rings have taken advantage, using SpyEye to send commands to tens of thousands of infected PCs in the U.S. and Europe, according to Damballa research findings.
In the first six months of the year, SpyEye was being used by 29 elite gangs that collectively commanded at least 2.2 million infected PCs worldwide. SpyEye normally sells for up to $10,000. But, as of last week, the latest, most powerful version of SpyEye could be acquired for just $95, says Bodmer.
How this sudden discounting came to be — and the resulting security implications — highlight how complex larceny on the Web has become over the past few years.
SpyEye surfaced in late-2009 as a bigger, badder rival to ZeuS, then the premier hacker’s toolkit.
SpyEye quickly surpassed ZeuS. By the end of 2010, it had evolved into a pricey, user-friendly software program — sold, updated and copyrighted, much like any legitimate business application.
For a base price of $6,000, SpyEye put a sophisticated Internet-based management tool into the hands of the buyer. Optional plug-in programs pushed the price to $10,000.
Anatomy of a heist
Using SpyEye, a criminal can issue commands to networks of thousands of bots. SpyEye-run botnets have proved to be unstoppable. Criminals use them to deliver spam scams, conduct hacktivist attacks and booby-trap legit websites with infections that create more bots.
What’s more, SpyEye may be best known for enabling thieves to orchestrate the systematic siphoning of cash from the online banking accounts of consumers and small organizations. Transactions security firm Trusteer has documented SpyEye-orchestrated banking account heists in action. SpyEye:
•Waits for the account holder to log into his or her online banking account.
•Collects the user’s balance figure and determines whether the account is ripe for theft.
•Initiates money transfers invisibly.
•Transfers funds into a mule account that is set up and controlled by the thief to receive cash transfers.
•Erases any evidence of the fraudulent transfer.
•Adds the stolen amount back to the official account balance, as if nothing is amiss.
“SpyEye is very dynamic and versatile,” says Amit Klein, Trusteer’s chief technical officer. “We see it pushing new builds to the field on a weekly basis. These frequent updates enable SpyEye to be more elusive and less detectable.”
Perpetual arms race
In early August, a French researcher, using the online handle Xyliton, discovered how to crack open SpyEye’s licensing key, which unlocks the software for full use, complete with a tutorial. In doing so, Xyliton disabled a feature that requires licensed users to designate a name to their copy of the toolkit in an attribution field. Good-guy researchers use this attribution field to keep track of which crime rings are actively using SpyEye. Xyliton then published his findings on the Internet.
Skilled hackers quickly created simple programs to access full versions of SpyEye and began selling them for about $100, Damballa’s Bodmer says.
Because of how the crack was carried out, the free and discounted versions of SpyEye recently put to use in attacks are much harder to distinguish, Bodmer says. “Not only is the toolkit now free or very cheap, but attributing usage to a specific criminal operator has become significantly more difficult,” he says.
There is debate in tech security circles about whether Xyliton’s disclosure did more harm than good. Some experts argue that tech security companies now have more detail about how cutting-edge hacking tools work, which should help with detection and filtering.
“White hats may now gain insight into the workings of (SpyEye), but this will not be the end of the perpetual arms race,” says Etay Maor, cybercrime specialist at RSA, the security division of EMC.
Maor predicts that SpyEye’s creators will fix the cracked licensing key, improve the core toolkit and push out advancements.
Others worry that botnets have been widely used this summer to conduct intensive Google searches — known as Google hacking — as part of campaigns to locate, then mass infect, more than 8 million Web pages published by smaller online merchants and professional firms. The PC of anyone who navigates to one of these infected small-business pages gets turned into a bot.
“Google hacking is often the first step to perform reconnaissance,” says Rob Rachwald, strategy director at security firm Imperva. “It’s very likely that SpyEye will be used for Google hacking, and leveraging SpyEye is imminent.”
grrgg
8:56 PM on August 21, 2011
Turn off scripts and only allow them on a per-site basis;
Block all third-party cookies;
Block all pop-ups;
Change your DNS from automatic, instead directing to Google’s DNS (IPv4 8.8.8.8 and 8.8.4.4) — search Google public DNS for background
Install browser add-ons that identify compromised websites in your search results;
Install browser add-ons that block flash, that you can then allow on a per-site basis;
Do not assume the free WiFi is secure — someone might set up a middle-man attack and fool you into connecting to their machine that tracks your actions;
When in doubt (especially on an open public WiFi network), always force HTTPS (by physically typing it into the address bar) or use the EFF’s HTTPS Everywhere for Firefox.
Hackers SpyEye
Pages
Posts
- Comment on Iran
- Democracy In China Delayed
- Egypt Spring Election
- Job Scams
- Obama and His Record
- Palestinian sic Egypt Spring
- 4th Virginia Textbook
- A Love Story
- ABC facts about China
- Acting like Assholes
- Afghanistan Behind US
- Afghanistan beyond 2011
- Afghanistan Pakistan Karzai
- Afghanistan Petraeus Karzai
- Afghanistan reality check
- Alabama what you think
- Amazing colorized photographs
- Amazing Elephant Rescue
- American Common Sense Immigration Reform
- American Dream in trouble
- Another Wall Street scam
- Arab Democracy touch of reality
- Arab Spring contrary opinion
- Arab Spring Egypt update
- Arab Spring ground zero
- Arab Spring in April
- Arab Spring in Mali cocaine
- Arab Spring Islamist Festival
- Arab Spring Outcome
- Arab Spring Reality
- Arab Spring Syria
- Arab Spring they hate US
- Arab Spring Update
- Arab Spring update
- Arab Spring update Libya
- Arizona Massacre
- BAD parenting means BAD kids
- BEWARE Islam in America
- Beyond Devotion to Service
- Bin Laden Dead Never Forget
- Black Issues
- Boston Marathon Tragedy
- Break up BIG Banks
- British heroes Luftwaffe interviews
- British military decline
- Broken Government Serves Politicians
- Budget Battle Bust
- Bush Book Decision Points
- Bush broke IRAQ no ownership
- Bush’s Iraq
- Bush’s lasting legacy
- Cambridge Holiday
- Cancer is a Modern Disease
- Cancer treatment shows promise
- China Changes Leaders
- China Currency
- China going forward 2012
- China in Focus
- China is a Sleeping Dragon
- China means cyber-warfare
- Chinese Advantages Problems
- Chinese business model
- Chinese consumerism
- Chris Christie don’t bet on it
- Christmas 2012
- Chronology of Failure
- Class warfare Facts
- Coca Cola secret formula
- Color photography 1940s
- coming soon Mexifornia
- Comment on 2012 Candidates
- Comment on the debt limit crisis
- Common Sense about Afghanistan
- Concentration Camps
- Conflict South China Sea
- Corporations NOT PAYING taxes
- Courage Faith Jessica Lynch
- Debt Deal Graphics
- Debt-ceiling imperative
- December 1860
- Declaration on Iran
- Detroit Schools – Archaeological Evidence
- Detroit Schools – SOS
- Dick Cheney doinks history
- Dick Morris predicts the election
- Dick Morris spins Bain Romney
- Disgraceful Treatment of VETerans HE SAVED MANY
- Divided State of America
- Dreams Deferred Dayton OH
- Dubya’s Disaster
- Economic Recovery – What Recovery?
- Education Means Individual Achievement
- Egypt in reality
- Egypt under Morsi
- Egyptian democracy prospects
- Election 2010
- Emily Perez an example
- Energy Independence Happy Fourth
- Energy Issues
- Equality of Opportunity Based upon Merit
- European Affairs Greece
- European Civilization
- European Economics – Russia – Germany – France – Italy
- Fact Check
- FACT Obama not a Leader
- Facts about China
- Facts About Climate Change
- Facts About Climate Change
- Facts About Entitlements
- Facts about Financial MELTdown
- Facts about High unEmployment
- Facts about Islam
- Facts About Medicare
- Facts about Mitt Romney
- Facts about NO Leadership and You
- Facts about North Korea
- Facts about Rick Santorum
- Facts about Taxes
- Facts about the debt deal
- Facts about the Iraq invasion
- Facts about the one perCent
- Facts about Trayvon Martin killing
- Facts on the Ground in Iraq
- Facts Rick Perry cronyism etc
- First Black Fighter Pilot Last Cavalry Charge
- Fiscal Cliff Chronology
- Fiscal Cliff Cometh
- Fiscal Cliff is here
- Flavor of the month Herman Cain
- Flood Photos
- Florida Foreclosures
- Four More Years
- FRANCE
- Gay Marriage
- Get Out of Afghanistan
- get the Money out of politics
- Global Warming is here
- Glory of God
- Goldman Sachs Naked and exposed Historical Inequality
- GOOD news POSITIVE stories
- Governor Walker is a Republican Ideologue
- Grover Norquist
- Hackers SpyEye
- Hamas strikes out
- Hard Times then and now
- Henry Kissinger gives advice
- Honest Abe Savior and Martyr
- How Catholic bishops operate
- How Did We Get Into This Mess
- How government works
- Hurricane Sandy Tragedy no one should die alone in darkness
- Hypocrites
- Ideology is ignorance
- Illegal Immigration attitudes
- illegal immigration What You Think
- Importance of BEES Colony Collapse
- Internet Issues cyber-warfare
- Islam in America
- Islam in Europe
- Jesse Owens American Hero
- Jim Martin Letter 101st Airborne
- Jim Tressel
- Jobs Jobs Jobs
- Judas the Galilean and his Unterbrink writings
- Keith Olbermann ko’d
- Kevin Phillips Predicts Future
- KFC conquers China
- Kick The comment on Comment
- La reConquista giving Our Country back to the Indians
- laissez faire capitalism – Where are the good jobs?
- Likely Libya Outcome
- Litigation in Libya
- Living in Paris
- Manufacturing creates wealth
- Marilyn Monroe unseen photographs
- Marine Life dying coral
- Medicare Mediscare Mega problems
- METH MESSes You Up
- Michael Redd Bucks
- Middle Class economy 21st cen
- Middle Class fACTs
- Middle Class Stories Change for the American Dream
- Mindless VIOLENCE and Senseless Cruelty
- Mitt Romney Bain Capital 2012 election
- More Climate Change FACTS
- MORE Divided than Ever
- More of the Same?
- MORE Soldier Stories HELP Taylor Morris
- Mullahs want the bomb
- Muslim Brotherhood revealed
- Muslim Democracy
- Neil Armstrong last interview
- Never Forget 9 11 Essay
- NEW 9-11 video
- New Pearl Harbor account
- Newsweek how Dumb Are We?
- Norway Nutjob Anders Behring Breivik
- NYC imam True Face of Islam
- Obama abandons white working class
- Obama AD 2010
- Obama affect on America
- Obama and Middle East Peace
- Obama and Syria
- Obama is a phony
- Obama no sense of humor
- Obama not the anti-Christ
- Obama Re-elected Watch Out
- Obama Scorecard
- Obama supports gay marriage
- Obamacare is Poison
- Oceans are dying SOS planet
- Oil Prices means speculators
- Old Men Who Don’t Care
- On Planet Krauthammer
- Opinion about Fracking
- Opinion about Newt Gingrich
- Opinion about Obama
- Opinion about Romney
- Oregon Somali Terrorist
- Our country committing suicide
- Our Friends in Pakistan
- Pakistan Protected Osama bin-Laden updated
- Palin a Phony?
- Palin Book Tour
- past Present FUTURE America
- Pay Attention
- People Need Good Jobs
- Pluto in Capricorn
- Polar Bear Family
- Political Correctness in the UK
- Prairie Chapel Ranch
- Pray for the Children
- Pray for the Children
- Predatory Chinese
- President Santorum
- Progress in Iraq no democracy
- Rare Earth
- Reality in Libya
- Republican Mandate?
- Robert Bales should be executed
- Rolling Stones at Fifty
- Romney and Afghanistan
- Romney and His Record
- Romney no military service
- Ron Paul
- Ronald Reagan Tax Review
- Ronald Reagan true myths
- SAD Obama
- Santa Muerte
- Secure Protect Your Data
- See The Evidence PHOTOGRAPHS
- Sesquicentennial of the Civil War
- Sgt Dennis Weichel and Afghanistan
- Snow Scenes around the world
- Soldier Stories
- SSG Johnson surprises Skylar – HAPPY
- State by State casualties Afghanistan
- State of our Democracy
- State of the Economy
- Stories about the After life Service is the currency of Salvation
- Stories World War I and II
- Supercommittee FAILure
- Syrian Spring updated
- Tea Party Hearty
- Ten Conditions for Change
- The Connected Class con
- The FED is private
- The Great Helmsman
- The Rich Get Richer
- There are the Jobs
- Trump for President
- Truth to power The People
- Tunisian Revolution
- U.S. Troops to Leave Iraq by Year’s End
- UNDERWATER PHOTOGRAPHY
- Unfair Competition equals Free Trade
- Veterans Aging Prematurely
- Veterans Issues
- Washington’s Farewell Address
- Waterloo and Trafalgar
- WEAKest President in History
- What about Scientology
- What Does Romney Stand For
- What President Morsi Really Thinks
- What you think about Obama
- What you think about Romney
- who cares gr$$dy NFL
- Why Romney Lost
- Wisdom about Fools
- Xi Jinping and China
- Xi Jinping new leader in China
- Zero Some Game










