Showing posts with label sinowal. Show all posts
Showing posts with label sinowal. Show all posts

Tuesday, May 5, 2009

Taking Over The Torpig Botnet - Report

The researchers of Santa Barbara University of California have published report of their ten days long takeover of Torpig (a.k.a. Sinowal,
Anserin) botnet took place at the beginning of 2009. Over this period, they observed more than 180 thousand infections and recorded more than 70 GB of data that the bots collected.

Collected data contained e.g. over 1,200,000 Windows passwords, over 54,000 mailbox account items and near 12,000,000 form data items which means the content of HTML forms submitted via POST requests by the victim’s browser.

Even more severe is that Torpig obtained credientals of over 8,310 accounts at 410 different financial institutions and 1,660 unique credit and debit card numbers.

"Quantifying the value of the financial information stolen by Torpig is an uncertain process because of the characteristics of the underground markets where it may end up being traded. A report by
Symantec
indicated (loose) ranges of prices for common goods
and, in particular, priced credit cards between $0.10–$25 and bank
accounts from $10–$1,000. If these figures are accurate, in ten days
of activity, the Torpig controllers may have profited anywhere be-
tween $83k and $8.3M"

Complete report can be found here.

Monday, November 3, 2008

Over 300,000 Bank Accounts Compromised By Sinowal

Security company RSA writes in its blog about Sinowal Trojan (aka Torpiq and Mebroot) which may be the worst and the most advanced crimeware ever created by fraudsters. During its existence (from early February 2006) Sinowal has compromised and stolen login credentials from approximately 300,000 online bank accounts as well as a similar number of credit and debit cards. Other information such as email, and FTP accounts from numerous websites, have also been compromised and stolen. In the past six months alone login credientals and information of over 100,000 online bank accounts have been stolen by this Trojan.

The source of Sinowal has been speculated a lot. Some speculations say that it has been operated and hosted by a Russian online gang with past ties to the Russian Business Network (RBN). "Our data confirms the Sinowal Trojan has had strong ties to the RBN in the past, but our research indicates that the current hosting facilities of Sinowal may have changed and are no longer connected to the RBN", writes RSA in the blog. It's no doubt interesting that the Trojan has stolen banking account information all over the world but Russian accounts have been left alone.