Chinaunix首页 | 论坛 | 博客
  • 博客访问: 1411556
  • 博文数量: 416
  • 博客积分: 13005
  • 博客等级: 上将
  • 技术积分: 3297
  • 用 户 组: 普通用户
  • 注册时间: 2006-04-05 16:26
文章分类

全部博文(416)

文章存档

2014年(1)

2013年(4)

2012年(46)

2011年(64)

2010年(12)

2009年(4)

2008年(40)

2007年(187)

2006年(58)

分类: 网络与安全

2011-08-19 22:41:22

http://blog.eset.com/2011/08/16/win32kelihos-recruiting-in-a-country-near-you

Win32/Kelihos, Recruiting in a Country Near You
by Pierre-Marc Bureau
August 16, 2011 at 11:39 am
2

As part of our botnet monitoring initiative, we recently stumbled across an interesting piece of news. The Win32/Kelihos botnet, a likely successor to Win32/Waledac and Win32/Nuwar (the infamous Storm worm), is now sending spam to recruit money mules. We captured two different spam templates used by the bot to generate spam messages. As shown in the images below, the recruitment advertisements are in two languages, German and Portuguese.

We often see mule recruitment spam but it is usually in English. This is a likely proof that standard recruitment schemes are getting less successful and malicious actors need to spend more energy on targeted audience in their native language. Another possibility would be that the malware operators are specifically looking for money mules in Portugal and Germany. In the last couple of weeks, the Win32/Kelihos botnet was used for pump and dump scams, it is likely the operators are now moving to the next step of their operation which is to transform their gain on the stock market into cash.

If you are interested in peer-to-peer botnets and the evolution of Win32/Kelihos, we will at the upcoming Virus Bulletin conference in Barcelona.

Thanks to Sebastien Duquette and Alexis Dorais-Joncas for their help in this research.

Pierre-Marc Bureau
Senior Malware Researcher

2 Responses to “Win32/Kelihos, Recruiting in a Country Near You”
  1. Reggie Gates Says:
    August 16th, 2011 at 2:21 pm

    OK, I'll ask…what is a money mule and what does Win32/Kelihos botnet do?  For us less technically orientated folks, more explanation would be helpful.
     
    Thanks
    R Gates

  2. David Harley Says:
    August 17th, 2011 at 1:41 pm

    This might answer your question about money mules: As Pierre-Marc indicates, Kelihos is, like most active botnets, used for a range of activities (whatever makes money…). Earlier in its career, it was particularly associated with the theft of FTP passwords. Recently, it’s been used for stockmarket scams (a pump and dump scheme persuades people to buy low-value stock at an inflated price so that the scammer can sell it off at a large profit before it returns to a more realistic level). Pierre-Marc is, I think, suggesting that recruiting people to do moneylaundering is the next step in its monetizationn process.


阅读(444) | 评论(0) | 转发(0) |
0

上一篇:1000 days of Conficker

下一篇:Inside Carberp Botnet

给主人留下些什么吧!~~