Virusbuster
virus
Virus types
Virus encyclopedia
Hoaxes
How to realize an effective virus protection?
Virus toplist
Send virus samples
site search

database update
Our most recent downloadable database:
version:
10.87.6

date:
08. september 2008
Massive cache of stolen data
Printer friendly version
Thousands of employees of corporations, healthcare orgs, government agencies & others infected by Trojan Coreflood

SecureWorks announced that the firm has uncovered one of the largest caches of stolen hacker data ever reported, if not the largest. The hacking scam involves thousands of employees of hundreds of organizations worldwide who have been infected with the information-stealing Trojan Coreflood - also known as AFcore - and its variants.

What makes this hacker scheme so unique is that it has flown under the radar for years and the hacking group behind it has been able to go in and infect hundreds of employees of individual organizations via network administrator privileges.

Essentially, the hackers infect one employee’s workstation and then lie in wait for the organization’s network administrator to log on to that infected workstation. Once the administrator logs on, then the hacker will run the Trojan under the administrator’s username and password and subsequently infects all the workstations that the administrator has privileges to.

The Trojan not only captures usernames and passwords, but also grabs the text content of the page at the same time. This would allow the criminal to possibly find credentials that he/she may not have even realized was valuable, as well as giving a quick way to determine value of credentials for instance, by displaying the bank account balance of the infected user. Not having to log in to each account to determine its balance can be a huge time saver for a criminal.

Although it would take a great deal of time to determine just how much money the Coreflood group has illicit access to, based on numbers seen in the database it is easily in the millions of dollars.


Source: darkREADING
Printer friendly versionTop of page