<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CoreTrace WhiteSpace&#187; CoreTrace WhiteSpace</title>
	<atom:link href="http://www.coretraceblogs.com/tag/botnet/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.coretraceblogs.com</link>
	<description>The Application Whitelisting and Security Weblog</description>
	<lastBuildDate>Fri, 27 Jan 2012 17:47:15 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Godzilla versus King Kong, bot style? Zeus versus Ares&#8230; (and why neither wants to face Bouncer)</title>
		<link>http://www.coretraceblogs.com/2010-11/godzilla-versus-king-kong-bot-style-zeus-versus-ares-and-why-neither-wants-to-face-bouncer/</link>
		<comments>http://www.coretraceblogs.com/2010-11/godzilla-versus-king-kong-bot-style-zeus-versus-ares-and-why-neither-wants-to-face-bouncer/#comments</comments>
		<pubDate>Tue, 30 Nov 2010 14:24:26 +0000</pubDate>
		<dc:creator>Toney Jennings</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[whitelisting]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[ares]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[Zeus]]></category>

		<guid isPermaLink="false">http://www.coretraceblogs.com/?p=2519</guid>
		<description><![CDATA[Over the past few years, the Zeus virus has infected millions of financial systems worldwide, capturing account credentials that cybercriminals use to gain access to corporate networks and steal sensitive data. While there have been competitive programs designed to dethrone Zeus and remove the widespread malware from infected systems, a newly announced malicious software is [...]]]></description>
			<content:encoded><![CDATA[<p>Over the past few years, the Zeus virus has infected millions of financial systems worldwide, capturing account credentials that cybercriminals use to gain access to corporate networks and steal sensitive data. While there have been competitive programs designed to dethrone Zeus and remove the widespread malware from infected systems, a newly announced malicious software is threatening to one-up the infamous do-it-yourself banking Trojan.<span id="more-2519"></span></p>
<p>According to the article, <a href="http://www.infoworld.com/t/malware/coming-soon-clash-the-banking-trojans-875" target="_blank">&#8220;Coming soon: &#8216;Clash of the Banking Trojans&#8217;,&#8221;</a> a malware programmer plans to release a program known as &#8220;Ares&#8221;. The malicious software is &#8220;a small, lightweight executable that can evade antivirus and be easily placed into PDFs and other exploitable files.&#8221;</p>
<p>Despite these unique features, what distinguishes Ares from other malware is a module platform that enables criminals to customize and update it to meet their specific needs. In a post on a criminal online forum, the developer said Ares gives a buyer of the malicious code something other programs don&#8217;t &#8212; a choice.</p>
<p>&#8220;I actually consider this more of a platform which is customized to each buyers liking. This is what draws a line between Ares and other bots.&#8221;</p>
<p>While Ares remains only a threat, if released, security experts say the new Trojan could pose a serious danger as it rolls out in numerous versions and targets different businesses. However, systems protected by CoreTrace&#8217;s <a href="http://www.coretrace.com/products/BOUNCER_by_CoreTrace/default.aspx" target="_blank">BOUNCER application whitelisting solution</a> need not worry. No matter how the program is customized, BOUNCER proactively blocks all attempts the malicious code makes to run on a system, thereby beating down any new customizable malicious software such as Ares and other malware variants that try to execute on a machine.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.coretraceblogs.com/2010-11/godzilla-versus-king-kong-bot-style-zeus-versus-ares-and-why-neither-wants-to-face-bouncer/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>From the &#8220;what more proof do you need?&#8221; file: 90% of the most secure firms may be affected by botnets&#8230;</title>
		<link>http://www.coretraceblogs.com/2010-04/from-the-what-more-proof-do-you-need-file-90-of-the-most-secure-firms-may-be-affected-by-botnets/</link>
		<comments>http://www.coretraceblogs.com/2010-04/from-the-what-more-proof-do-you-need-file-90-of-the-most-secure-firms-may-be-affected-by-botnets/#comments</comments>
		<pubDate>Thu, 15 Apr 2010 18:17:08 +0000</pubDate>
		<dc:creator>Toney Jennings</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[cyber defense]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[malware attacks]]></category>
		<category><![CDATA[RSA]]></category>
		<category><![CDATA[Zeus Trojan]]></category>

		<guid isPermaLink="false">http://www.coretraceblogs.com/?p=1580</guid>
		<description><![CDATA[An RSA study released on Wednesday claims that most major U.S. corporations &#8212; including up to 88% of Fortune 500 companies &#8212; may be affected by botnet activity from computers compromised by the Zeus Trojan.
In the article, &#8220;88 percent of firms show Zeus botnet activity,&#8221; RSA’s FraudAction Anti-Trojan services analyzed data stolen by Zeus from [...]]]></description>
			<content:encoded><![CDATA[<p>An RSA study released on Wednesday claims that most major U.S. corporations &#8212; including up to 88% of Fortune 500 companies &#8212; may be affected by botnet activity from computers compromised by the Zeus Trojan.</p>
<p>In the article, <a href="http://news.cnet.com/8301-27080_3-20002425-245.html">&#8220;88 percent of firms show Zeus botnet activity,&#8221;</a> RSA’s FraudAction Anti-Trojan services analyzed data stolen by Zeus from infected computers that included IP addresses and emails that belonged to the corporations. Among the stolen data found on the sites where infected computers drop the stolen data was compromised email addresses from about 60% of the firms.<span id="more-1580"></span></p>
<p>With such a high percentage of botnet activity hitting Fortune 500 companies, it just goes to show that even the biggest, theoretically most advanced companies from a security standpoint are not immune to being hit by infectious malware.</p>
<p>It all circles back to a recent posting on what we’re doing today to improve our cyber defenses. In the blog, <a href="http://www.coretraceblogs.com/2010-04/repercussions-not-legislation-key-to-improving-nations-cyber-defenses/">&#8220;Repercussions, not legislation, key to improving nation&#8217;s cyber defenses,&#8221;</a> I mentioned that we need to get out of the status quo network security practices and techniques that are flawed, and start thinking in a more proactive manner. Until we do, our systems will remain at risk of hidden malicious code and malware attacks designed to snoop and steal our sensitive data, whether we know it or not.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.coretraceblogs.com/2010-04/from-the-what-more-proof-do-you-need-file-90-of-the-most-secure-firms-may-be-affected-by-botnets/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Top Endpoint Security Stories for November 2009</title>
		<link>http://www.coretraceblogs.com/2009-12/top-endpoint-security-stories-for-november-2009/</link>
		<comments>http://www.coretraceblogs.com/2009-12/top-endpoint-security-stories-for-november-2009/#comments</comments>
		<pubDate>Thu, 03 Dec 2009 20:09:56 +0000</pubDate>
		<dc:creator>Toney Jennings</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[CoreTrace]]></category>
		<category><![CDATA[endpoint protection]]></category>
		<category><![CDATA[patching]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.coretraceblogs.com/?p=957</guid>
		<description><![CDATA[November was a busy month for security stories. The month kicked off with more stories of massive security patches from both Microsoft and Apple leaving me to wonder when the patching madness will ever end. Windows 7 was found to have a flaw that allows denial of service attacks. Internet Explorer v7 (IE7) even made [...]]]></description>
			<content:encoded><![CDATA[<p>November was a busy month for security stories. The month kicked off with more stories of massive security patches from both Microsoft and Apple leaving me to wonder when the patching madness will ever end. Windows 7 was found to have a flaw that allows denial of service attacks. Internet Explorer v7 (IE7) even made it into the news with the latest vulnerability, but I question efforts to patch an aging application, why not just upgrade or use <a href="http://www.mozilla.com/en-US/firefox/firefox.html" target="_blank">Firefox</a>? If they aren&#8217;t willing to upgrade, do people really think they will patch IE7?</p>
<p>Without further delay, here are the stories that caught my eye in November:<span id="more-957"></span></p>
<ul>
<li class="margin_bottom_1em"><strong>Apple issues a massive security patch of its own</strong> – In November <a href="http://threatpost.com/en_us/blogs/apple-plugs-58-holes-monster-mac-os-x-update-110909" target="_blank">Apple issued a patch that fixed 58 holes</a> as reported by Threatpost. The days of Apple being immune to security compromise are over. The combination of phishing and browser based attacks should make Mac users concerned and will soon drive security solutions adoption on those systems.</li>
<li class="margin_bottom_1em"><strong>Microsoft is back with it&#8217;s own large security patch</strong> – Microsoft fixed <a href="http://www.computerworlduk.com/technology/operating-systems/windows/news/index.cfm?newsid=17501" target="_blank">15 separate vulnerabilities with 6 security updates </a>in November. This is the same old story as previous months, but at least it wasn&#8217;t the record 13 updates hit in October.</li>
<li class="margin_bottom_1em"><strong>Microsoft reported an increase in worm infections, but decrease in scareware antivirus</strong> – Worm infections were up over 98% since the last Microsoft Security Intelligence report and it appears that Conficker bears a good part of the blame. Researchers believe that it is still being spread by USB keys with autoexecute capabilities. Scareware numbers are down where a user is tricked into visiting a site that says they are infected and then prompted to download &#8220;protection&#8221; from the malware.</li>
<li class="margin_bottom_1em"><strong>More news of botnet operators utilizing social networks to avoid detection</strong> – Searchsecurity.com reported that <a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1373974,00.html?track=sy160" target="_blank">botnet writers are turning to Google and social networks</a>. Popular social networking sites like Facebook and Twitter are increasingly prominent in security news for both spreading infection and providing a means of command and control for organized malicious software writers.</li>
<li class="margin_bottom_1em"><strong>Four people were sentenced in the UK for attacks on online banks</strong> – This is something I would like to see more of. It is a rare occurrence when cyber criminals are actually tracked down and brought to justice. Last month <a href="http://www.itworld.com/security/84838/uk-hails-first-cybercrime-cooperation-banks" target="_blank">four individuals who were syphoning money from online accounts were caught and sentenced</a>. </li>
<li class="margin_bottom_1em">CSO online had a nice detailed story about the fight against botnets – CSO published a nice seven page story <a href="http://www.csoonline.com/article/507936/The_Botnet_Hunters_">about the individuals and organizations who research and combat botnets</a>. It&#8217;s an interesting and informative read.</li>
<li><strong>Windows 7 is revealed to have flaw that allows DoS attacks</strong> &#8211; <a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1374572,00.html?track=sy160&#038;utm_source=feedburner&#038;utm_medium=feed&#038;utm_campaign=Feed%3A+techtarget%2FSearchsecurity%2FSecurityWire+%28SearchSecurity+%3A+Security+Wire+Daily+News%29" target="_blank">A flaw in the OSs Server Message Block (SMB) could be used to crash the system</a> and could be activated when a user visits a malicious website.</li>
</ul>
<p>There were several other interesting stories, but the fact remains that endpoints are under attack and we are in a continual catch up game with our current endpoint security.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.coretraceblogs.com/2009-12/top-endpoint-security-stories-for-november-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Social network security key issue for business in 2010</title>
		<link>http://www.coretraceblogs.com/2009-11/social-network-security-key-issue-for-business-in-2010/</link>
		<comments>http://www.coretraceblogs.com/2009-11/social-network-security-key-issue-for-business-in-2010/#comments</comments>
		<pubDate>Fri, 20 Nov 2009 17:15:12 +0000</pubDate>
		<dc:creator>JT Keating</dc:creator>
				<category><![CDATA[whitelisting]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[social networks]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[whitelist]]></category>

		<guid isPermaLink="false">http://www.coretraceblogs.com/?p=867</guid>
		<description><![CDATA[There have been many cases of social networks overlapping security software this year. Whether they are using Twitter or Facebook for botnet control or propagating phishing links through shortened URLs, online criminals are finding ways to tap into the explosive growth of social networks and use that to exploit end users and their devices.
A recent [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.coretraceblogs.com/wp-content/uploads/2009/11/iStock_socialmedia_server-211x227.jpg" alt="Social network security key for business in 2010" title="Social network security key for business in 2010" width="211" height="227" class="alignright size-medium wp-image-872" />There have been many cases of social networks overlapping security software this year. Whether they are using <a href="http://www.internetnews.com/security/article.php/3834721/Twitter+Used+as+Botnet+Control.htm" target="_blank">Twitter or Facebook for botnet control</a> or <a href="http://www.businessweek.com/smallbiz/tips/archives/2009/10/the_dangers_lur.html" target="_blank">propagating phishing links through shortened URLs</a>, online criminals are finding ways to tap into the explosive growth of social networks and use that to exploit end users and their devices.</p>
<p>A recent article in SearchSecurity.com, <a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1374907,00.html?track=sy160&#038;utm_source=feedburner&#038;utm_medium=feed&#038;utm_campaign=Feed%3A+techtarget%2FSearchsecurity%2FSecurityWire+%28SearchSecurity+%3A+Security+Wire+Daily+News%29" target="_blank">&#8220;Hackers to sharpen malware, malicious software in 2010&#8243;</a>, points to increasing sophistication in cybercriminals&#8217; use of social networking sites.<span id="more-867"></span> Robert Westervelt writes:</p>
<blockquote>
<p>In an effort to sustain growth and pick up new users, more social networks are opening up their architecture to allow third-party applications. Cybercriminals can take advantage of this by developing applications out of the social network environment to target users. In addition, access to social network APIs gives attackers a roadmap to vulnerabilities in legitimate third-party applications and a way to tap into user accounts.</p>
</blockquote>
<p>Changes in this environment means that businesses will be more pressed than ever to set policies around the use of social networks on company IT resources and this won&#8217;t be popular. It will be made all the more difficult by the fact that social networks aren&#8217;t just for personal use any more. More businesses than ever are engaging in social media and using it to connect to customers, provide service, and promote their company.</p>
<p>Expect web site access control, application whitelisting and software asset management solutions to play an even more important role than ever on corporate networks. It will be essential that businesses both understand and control what applications their employees are using to defend against an increasingly prevalent threat.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.coretraceblogs.com/2009-11/social-network-security-key-issue-for-business-in-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Don&#8217;t miss the point of 60 Minutes grid security story &#8211; Cyber threats are real</title>
		<link>http://www.coretraceblogs.com/2009-11/dont-miss-the-point-of-60-minutes-grid-security-story-cyber-threats-are-real/</link>
		<comments>http://www.coretraceblogs.com/2009-11/dont-miss-the-point-of-60-minutes-grid-security-story-cyber-threats-are-real/#comments</comments>
		<pubDate>Mon, 16 Nov 2009 16:56:31 +0000</pubDate>
		<dc:creator>Toney Jennings</dc:creator>
				<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[electric grid]]></category>
		<category><![CDATA[endpoint protection]]></category>

		<guid isPermaLink="false">http://www.coretraceblogs.com/?p=852</guid>
		<description><![CDATA[In the wake of the 60 Minutes story there has been both a significant amount of attention given to the story online as well as expected complaints that the story was over hyped. The specific complaint was the citation by &#8220;prominent intelligence sources&#8221; that the Brazilian power outage was caused by cyber attacks. I even [...]]]></description>
			<content:encoded><![CDATA[<p>In the wake of the <a href="http://www.cbsnews.com/stories/2009/11/06/60minutes/main5555565.shtml?tag=currentVideoInfo;segmentUtilities" target="_blank">60 Minutes story</a> there has been both a significant amount of attention given to the story online as well as expected complaints that the story was over hyped. The specific complaint was the citation by &#8220;prominent intelligence sources&#8221; that the Brazilian power outage was caused by cyber attacks. I even received some tweets dinging me for propagating the hype from my <a href="http://www.coretraceblogs.com/2009-11/60-minutes-highlights-threats-to-our-power-grid/" target="_blank">last post on the original 60 minutes story</a>.</p>
<p>The complaint is that 60 Minutes didn&#8217;t do their homework and that there is no proof that the actual outage was caused by hackers. I won&#8217;t get dragged into that dispute here, but I would like to address the conclusion that some have made that hacking in general is overstated.</p>
<p>To those who work in the security industry and say that the cyber threat to both Government and private systems is over hyped, my answer is have they even been paying attention? Both foreign governments and organized online crime have been carrying out attacks with specific purposes with increasing frequency and the evidence is all around us.<span id="more-852"></span></p>
<p>Here are some examples:</p>
<ul>
<li class="margin_bottom_1em">
<p><strong>From 60 Min story – U.S. Government loses over a terabyte of sensitive information</strong>:</p>
<blockquote>
<p>&#8220;In 2007 we probably had our electronic Pearl Harbor. It was an espionage Pearl Harbor,&#8221; Lewis said. &#8220;Some unknown foreign power, and honestly, we don&#8217;t know who it is, broke into the Department of Defense, to the Department of State, the Department of Commerce, probably the Department of Energy, probably NASA. They broke into all of the high tech agencies, all of the military agencies, and downloaded terabytes of information.&#8221;</p>
</blockquote>
</li>
<li class="margin_bottom_1em">
<p><strong>Hackers steal over 130 million credit card numbers online</strong> – In August Albert Gonzales was indicted for stealing <a href="http://www.bloomberg.com/apps/news?pid=20601101&#038;sid=aMXMq__dm_Z8" target="_blank">over 130 million credit card numbers</a> from Heartland and other online businesses.</p>
</li>
<li class="margin_bottom_1em">
<p><strong>Clampi trojan steals bank login information</strong> – Cnet posted a good article on the organized use of <a href="http://news.cnet.com/8301-27080_3-10298233-245.html" target="_blank">trojan horses to monitor our online activity and steal our credentials</a> when we visit one of over 4600 banking sites.</p>
</li>
<li class="margin_bottom_1em">
<p><strong>Bahama botnet used to drive online click fraud</strong> – From a recent <a href="http://securitywatch.eweek.com/click_fraud/botnet_clickfraud_problem_growing.html" target="_blank">eWeek article</a>:</p>
<blockquote>
<p>Click Forensics, which has been reporting on click fraud data and trends for over four years now, released its figures for Q3 2009 this week. According to the latest figures, botnet-driven traffic accounted for 42.6 percent of all the empty ad traffic between the beginning of July and the end of September 2009.</p>
<p>The results represents a significant increase in such activity, more than doubling botnet-driven click fraud compared to the same period in 2007 and gaining from the 27.5 percent reported for the same quarter in 2008.</p>
</blockquote>
</li>
</ul>
<p>These aren&#8217;t random infections from worms. This is organized hacking with a purpose. These are just a few real examples of our systems under attack and there are far more that simple searches will reveal. Our online systems are targets plain and simple and the security of our power grid is serious business.</p>
<p>If there is one thing that I hope people get from the 60 minutes story it&#8217;s that we need to understand the threats that exist out there and take the steps to mitigate that risk before a serious attack takes place. We have to remember that all significant threats can be considered FUD before they happen. When it comes to protecting our critical infrastructure I hope we don&#8217;t stick our head in the sand.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.coretraceblogs.com/2009-11/dont-miss-the-point-of-60-minutes-grid-security-story-cyber-threats-are-real/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

