
Law enforcement chiefs on both sides of the Atlantic are giving a fourteen-day warning about a new cyber crime networkThe UK government’s National Crime Agency (NCA) and the American Federal Bureau of Investigation (FBI) are urging all computer owners to take steps to secure their laptops and business systems in the face of a new version of the Zeus botnet. Thanks to Dell secure Works, the botnet has been disrupted – for now. But over the next two weeks the criminals are expected to fix it. So steps must be taken now to protect our data.
Game Over
Zeus first appeared several years ago, and the latest iteration is called ‘Game Over’ or GOZeus. It works by enslaving computers – which could be individuals’ laptops or part of a business system. They then become part of a rogue network or botnet, used by the criminals to suck data such as passwords, ID and credit card details from the computers. These details are then offered for sale in an online black market, with one person’s details typically costing around five dollars. The criminals sell or rent the stolen details in block of 100. Officially fifteen thousand computers have already been turned into ‘zombies’ working for Zeus. But FI editor Peter Warren’s sources say the true figure is closer to a quarter of a million.
Ransom
Not content with stealing and selling-on or renting personal details – including video screenshots of the login process, showing how different passwords are used – the criminals who control the botnet also use ransomware called the Crypto Locker which encrypts the victims’ computer. That means that the owner must pay a ransom to the criminals in order to regain access to the computer and all its confidential and commercially-sensitive files.
Cyber security company Dell Secure Works worked with the authorities to isolate the infected computers, known as zombies, in the GOZeus botnet by isolating its command and control centre.
According to Brett Stone-Gross, researcher at the University of California Santa Barbara, the botnet that has been taken down is not large but poses a significant threat. Click here to listen
David Dagon of Georgia Technical University – the founder of the Damballa cyber security company – worked on the research team that reverse-engineered the algorithm used by the Zeus command-and-control system. This enabled ethical hackers to intercept messages sent across the botnet. GOZeus works by de-centralising and randomising the process of command and control, using a switching mechanism like a relay race, with each computer in turn performing a commanding role and then ‘passing the baton’ to another outpost of the botnet which may be in another continent. Dagon also devised The Sink Hole, which disables the Crypto Locker ransomware. He tells FI Editor Peter Warren that the Zeus botnet is persistent and pernicious because its code is ‘open source’ – anyone can access it and develop new variants. Click to listen
The UK government’s National Crime Agency has issued press releases and media alerts urging all computer users to log on to its website GetSafeOnline. The response was such that the website crashed in the first day but is now functioning normally.
https://www.getsafeonline.org/news/we-have-short-time-to-beat-powerful-computer-attack/
It urges computer users to download a free software virus removal tool, update anti virus software, patch the computer and install a firewall.
FI editor Peter Warren – who chairs the Cyber Security Research Institute – adds the following safety advice:
“ Find an anti-virus software that lets you create a whitelist of all the different softwares that you want to run on your computer or computers. And create a new profile for yourself, so that you never log in as ‘administrator’. That way only software that is on your whitelist will be allowed to run. And when you are updating or downloading new software you will be challenged every time because you are not the administrator. This gives you a chance to really scrutinise the new software that you are adding, to make sure it doesn’t come with any ‘hidden extras’ that could suck you into a botnet.”
For more advice and information sign up for our regular newsletter and visit our sister website www.csri.info



