<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Italian Honey Project &#187; Press</title>
	<atom:link href="http://www.honeynet.it/category/press/feed" rel="self" type="application/rss+xml" />
	<link>http://www.honeynet.it</link>
	<description>The Italian chapter of the Honeynet Research Alliance</description>
	<lastBuildDate>Wed, 11 Jan 2012 11:44:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>SpyEye Trojan stole $3.2 million from US victims</title>
		<link>http://www.honeynet.it/botnet/spyeye-trojan-stole-3-2-million-from-us-victims</link>
		<comments>http://www.honeynet.it/botnet/spyeye-trojan-stole-3-2-million-from-us-victims#comments</comments>
		<pubDate>Fri, 23 Sep 2011 09:25:08 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Press]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[money loss]]></category>
		<category><![CDATA[SpyEye]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=424</guid>
		<description><![CDATA[
THN : The Hacker News. : A Russian cybergang headed by a mysterious ringleader called ‘Soldier’ were able to steal $3.2 million (£2 million) from US citizens earlier this year using the SpyEye-Zeus data-stealing Trojan, security company Trend Micro has reported and Trusteer reports that an Android variant of Spitmo (SpyEye for mobile) has been discovered. The [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p><a href="http://thehackernews.com/2011/09/spyeye-trojan-stole-32-million-from-us.html">THN : The Hacker News</a>. : A Russian cybergang headed by a mysterious ringleader called ‘Soldier’  were able to steal $3.2 million (£2 million) from US citizens earlier  this year using the SpyEye-Zeus data-stealing Trojan, security company  Trend Micro has reported and Trusteer reports that an Android variant of  <strong>Spitmo</strong> (SpyEye for mobile) has been discovered. The methodology  sounds familiar for those familiar with ZeuS Mitmo and SpyEye Spitmo:  infected computers inject a message into targeted netbanks prompting  their customers to install software on their phones. Once Spitmo is  installed, the SpyEye attacker is able to monitor incoming SMS and to  steal MTAN authentication messages.</p>
<p>&#8220;<em><span class="Apple-style-span" style="color: #990000;">His botnet  was able to compromise approximately 25,394 systems between April 19,  2011 and June 29, 2011. And while nearly all of the victims were located  in the US, there were a handful of victims spread across another 90  countries</span></em>,&#8221; it said in a blog post.</p>
<p>[…]</p>
<p>&nbsp;</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/spyeye-trojan-stole-3-2-million-from-us-victims/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Virgin alerts infected customers after SOCA&#8217;s advice</title>
		<link>http://www.honeynet.it/press/virgin-alerts-infected-customers-after-socas-advice</link>
		<comments>http://www.honeynet.it/press/virgin-alerts-infected-customers-after-socas-advice#comments</comments>
		<pubDate>Tue, 21 Jun 2011 11:27:00 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Press]]></category>
		<category><![CDATA[ISP]]></category>
		<category><![CDATA[legal]]></category>
		<category><![CDATA[removal]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=415</guid>
		<description><![CDATA[
About 1,500 customers of internet service provider Virgin Media have been warned that their PCs are infected with a malicious virus.[..] Virgin is understood to be the first UK ISP to give specific warnings about viruses based on SOCA&#8217;s advice. [..] Virgin company stressed that it had not been monitoring user activity, rather some of [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>About 1,500 customers of internet service provider Virgin Media have  been warned that their PCs are infected with a malicious virus.[..]</p>
<p>Virgin is understood to be the first UK ISP to give specific warnings about viruses based on SOCA&#8217;s advice. [..]</p>
<p><span class="Apple-style-span" style="border-collapse: separate; color: #000000; font-family: Times; font-size: 16px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;"><span class="Apple-style-span" style="color: #222222; font-family: 'Lucida Grande',Verdana,Arial,Helvetica,sans-serif; font-size: 12px; line-height: 15px;">Virgin company stressed that it had not been monitoring user activity, rather some of their customers&#8217; IP addresses were found by law enforcement while investigating criminal botnets.</span></span>[..]</p></blockquote>
<p>via <a href="http://www.bbc.co.uk/news/technology-13798122">BBC News &#8211; Virgin alerts infected customers</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/press/virgin-alerts-infected-customers-after-socas-advice/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>UK Police hits Zeus botnet</title>
		<link>http://www.honeynet.it/botnet/uk-police-hits-zeus-botnet</link>
		<comments>http://www.honeynet.it/botnet/uk-police-hits-zeus-botnet#comments</comments>
		<pubDate>Thu, 30 Sep 2010 07:49:56 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Press]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[LEO]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=360</guid>
		<description><![CDATA[
In the latest of a series of arrests to be made in relation to online bank fraud, the Met’s e-crime unit has struck again, taking 19 alleged cyber-criminals into custody. The gang is suspected of having stolen some £6 million over the last three months, according to the BBC News (just enough money for them [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>In the latest of a series of arrests to be made in relation to online bank fraud, the Met’s e-crime unit has struck again, taking 19 alleged cyber-criminals into custody.</p>
<p>The gang is suspected of having stolen some £6 million over the last three months, according to the BBC News (just enough money for them to be able to construct their own bionic man).</p></blockquote>
<p>via <a href="http://www.techwatch.co.uk/2010/09/29/police-nab-19-over-zeus-botnet-bank-fraud/">Police nab 19 over Zeus botnet bank fraud</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/uk-police-hits-zeus-botnet/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Belgian pump and dump botnet</title>
		<link>http://www.honeynet.it/botnet/belgian-pump-and-dump-botnet</link>
		<comments>http://www.honeynet.it/botnet/belgian-pump-and-dump-botnet#comments</comments>
		<pubDate>Tue, 22 Jun 2010 15:46:12 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Press]]></category>
		<category><![CDATA[Financial]]></category>
		<category><![CDATA[Financial Botnet]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=276</guid>
		<description><![CDATA[
According to a report in Belgian newspaper De Tijd, malware has been used to compromise the online portfolios of Belgian investors. The botnet was then used to influence stock prices, making the criminals more than 100,000 Euros. The investigation has remained secret until today. “With a push of a button the botmaster instructs all the [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>According to a report in Belgian newspaper De Tijd,  malware has been used to compromise the online portfolios of Belgian investors. The botnet was then used to influence stock prices, making the criminals more than 100,000 Euros. The investigation has remained secret until today.</p></blockquote>
<blockquote><p>“<em><strong>With a push of a button the botmaster instructs all the  computers to buy or sell the same shares at the same time.</strong></em>“</p></blockquote>
<blockquote></blockquote>
<p>via <a href="http://countermeasures.trendmicro.eu/belgian-pump-and-dump-botnet/">Belgian pump and dump botnet » CounterMeasures</a>.</p>
<p>Although is an incident happened on April 2007, it should be seriously analyzed. Currently, Are the financial system&#8217;s security countermeasures so far away from 2007 ?  I think not.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/belgian-pump-and-dump-botnet/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Botnet Takes Control of Penn State Computer</title>
		<link>http://www.honeynet.it/botnet/botnet-takes-control-of-penn-state-computer</link>
		<comments>http://www.honeynet.it/botnet/botnet-takes-control-of-penn-state-computer#comments</comments>
		<pubDate>Wed, 09 Jun 2010 15:16:12 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Press]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=270</guid>
		<description><![CDATA[
Penn State University is dealing with yet another data breach situation this week after school officials discovered that a university computer was essentially commandeered by a botnet and was revealing the names, social security numbers and other personal information of 15,800 students. via Botnet Takes Control of Penn State Computer &#8211; www.esecurityplanet.com.
]]></description>
			<content:encoded><![CDATA[<blockquote><p>Penn State University is dealing with yet another data breach situation this week after school officials discovered that a university computer was essentially commandeered by a botnet and was revealing the names, social security numbers and other personal information of 15,800 students.</p></blockquote>
<p>via <a href="http://www.esecurityplanet.com/features/article.php/3886516/Botnet-Takes-Control-of-Penn-State-Computer.htm">Botnet Takes Control of Penn State Computer &#8211; www.esecurityplanet.com</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/botnet-takes-control-of-penn-state-computer/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Zeus-friendly ISP taken down</title>
		<link>http://www.honeynet.it/botnet/zeus-friendly-isp-taken-down</link>
		<comments>http://www.honeynet.it/botnet/zeus-friendly-isp-taken-down#comments</comments>
		<pubDate>Tue, 18 May 2010 07:50:42 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Press]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=258</guid>
		<description><![CDATA[
The latest in the string of &#8220;bulletproof&#8221; ISPs has been taken down on Friday after its upstream service provider DIGERNET has been disconnected. PROXIEZ-NET went down making its claims of being immune to shutdowns untrue. According to The Register just days before the shutdown PROXIEZ-NET found its way to the Spamhaus block list for &#8220;acting [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>The latest in the string of &#8220;bulletproof&#8221; ISPs has been taken down on Friday  after its upstream service provider  DIGERNET  has been disconnected.    PROXIEZ-NET went down  making its claims of being immune to shutdowns untrue. According to The Register  just days before the shutdown  PROXIEZ-NET found its way to the Spamhaus  block list for &#8220;acting as a ZeuS botnet C&amp;C or hosting binaries dropzones for the ZeuS botnet.&#8221;</p></blockquote>
<p>via <a href="http://www.net-security.org/malware_news.php?id=1343">Zeus-friendly ISP taken down</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/zeus-friendly-isp-taken-down/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How Cyber-Crooks Turn Stolen Data into Money on eBay</title>
		<link>http://www.honeynet.it/press/how-cyber-crooks-turn-stolen-data-into-money-on-ebay</link>
		<comments>http://www.honeynet.it/press/how-cyber-crooks-turn-stolen-data-into-money-on-ebay#comments</comments>
		<pubDate>Wed, 12 May 2010 13:37:54 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Press]]></category>
		<category><![CDATA[Underground Economy]]></category>
		<category><![CDATA[Financial Botnet]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=254</guid>
		<description><![CDATA[
In a quickswapping scheme, a cyber-crook will use sites such as eBay or Amazon to offer an expensive item at a cheap price, explained Mikko Hypponen, chief research officer at F-Secure. After a deal is reached, the scammer will make an enticing offer – they will agree to ship the item to the buyer and [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>In a quickswapping scheme, a cyber-crook will use sites such as eBay or Amazon to offer an expensive item at a cheap price, explained Mikko Hypponen, chief research officer at F-Secure. After a deal is reached, the scammer will make an enticing offer – they will agree to ship the item to the buyer and only accept payment after the person has checked it out.Next, the scammer will use credit card information he or she previously pilfered with malware such as Zeus to purchase the item and send it to the buyer. After the buyer sends the agreed payment via Western Union or WebMoney, the scammer disappears, leaving the person whose card was stolen with an illegal charge and the quickswapping buyer at risk of having the item confiscated by police as stolen merchandise.</p></blockquote>
<p>via <a href="http://www.eweek.com/c/a/Security/How-CyberCrooks-Turn-Stolen-Data-into-Money-on-eBay-603320/?kc=rss&amp;utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+RSS%2Feweeksecurity+%28eWEEK+Security%29&amp;utm_content=Google+Reader#close=1">How Cyber-Crooks Turn Stolen Data into Money on eBay &#8211; Security from eWeek</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/press/how-cyber-crooks-turn-stolen-data-into-money-on-ebay/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BlackEnergy Trojan v2 relased. Now can target Russian and Ukrainian Banks too.</title>
		<link>http://www.honeynet.it/botnet/new-blackenergy-trojan-targeting-russian-ukrainian-banks-darkreading</link>
		<comments>http://www.honeynet.it/botnet/new-blackenergy-trojan-targeting-russian-ukrainian-banks-darkreading#comments</comments>
		<pubDate>Fri, 05 Mar 2010 08:38:39 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Press]]></category>
		<category><![CDATA[BlackEnergy]]></category>
		<category><![CDATA[Financial Botnet]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=184</guid>
		<description><![CDATA[
RSA Conference 2010 &#8212; Russian hackers have written a more sophisticated version of the infamous BlackEnergy Trojan associated with the 2008 cyberattacks against Georgia that now targets Russian and Ukrainian online banking customers. . &#8220;The rules have changed,&#8221; Stewart says. &#8220;There was once an unwritten rule that they didn&#8217;t attack their own banks.&#8221; But like [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>RSA Conference 2010 &#8212; Russian hackers have written a more sophisticated version of the infamous BlackEnergy Trojan associated with the 2008 cyberattacks against Georgia that now targets Russian and Ukrainian online banking customers.</p>
<p>. &#8220;The rules have changed,&#8221; Stewart says. &#8220;There was once an unwritten rule that they didn&#8217;t attack their own banks.&#8221;</p>
<p>But like most cybercrime operations, money is money, and the BlackEnergy botnet gang appears to be expanding its operations for more profit.</p>
<p>While the Zeus Trojan remains the most popular Trojan, Stewart says BlackEnergy 2 can do things Zeus cannot, such as stealing online credentials plus DDoS-ing. BlackEnergy 2 also steals the user&#8217;s private encryption key. Stewart has written an analysis of the Trojan, available <a href="http://www.secureworks.com/research/threats/blackenergy2/?threat=blackenergy2" target="_blank">here</a>.</p></blockquote>
<p>via <a href="http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=223101487&amp;cid=RSSfeed">New BlackEnergy Trojan Targeting Russian, Ukrainian Banks &#8211; DarkReading</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/new-blackenergy-trojan-targeting-russian-ukrainian-banks-darkreading/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mariposa botnet. Another financial botnet that infected 12.7 computer (!?)</title>
		<link>http://www.honeynet.it/botnet/mariposa-botnet-another-financial-botnet-that-infected-12-7-computer</link>
		<comments>http://www.honeynet.it/botnet/mariposa-botnet-another-financial-botnet-that-infected-12-7-computer#comments</comments>
		<pubDate>Wed, 03 Mar 2010 08:44:57 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Media]]></category>
		<category><![CDATA[Press]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[Mariposa]]></category>
		<category><![CDATA[Spain]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=180</guid>
		<description><![CDATA[
SAN FRANCISCO (AP) &#8212; Authorities have smashed one of the world&#8217;s biggest networks of virus-infected computers, a data vacuum that stole credit cards and online banking credentials from as many as 12.7 million poisoned PCs. The &#8220;botnet&#8221; of infected computers included PCs inside more than half of the Fortune 1,000 companies and more than 40 [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>SAN FRANCISCO (AP) &#8212; Authorities have smashed one of the world&#8217;s biggest networks of virus-infected computers, a data vacuum that stole credit cards and online banking credentials from as many as 12.7 million poisoned PCs.</p>
<p>The &#8220;botnet&#8221; of infected computers included PCs inside more than half of the Fortune 1,000 companies and more than 40 major banks, according to investigators.</p>
<p>Spanish investigators, working with private computer-security firms, have arrested the three alleged ringleaders of the so-called Mariposa botnet, which appeared in December 2008 and grew into one of the biggest weapons of cybercrime. More arrests are expected soon in other countries.</p>
<p>Spanish authorities have planned a news conference for Wednesday in Madrid.</p>
<p>[....]</p>
<p>Also, the suspects go against the stereotype of genius programmers often associated with cyber crime. The suspects weren&amp;apos;t brilliant hackers but had underworld contacts who helped them build and operate the botnet, Cesar Lorenza, a captain with Spain&amp;apos;s Guardia Civil, which is investigating the case, told The Associated Press.</p>
<p>Investigators were examining bank records and seized computers to determine how much money the criminals made.</p>
<p>[....]</p></blockquote>
<p>via <a href="http://hosted.ap.org/dynamic/stories/U/US_TEC_BOTNET_BUSTED?SITE=AP&amp;SECTION=HOME&amp;TEMPLATE=DEFAULT&amp;CTIME=2010-03-02-14-26-32">News from The Associated Press</a>.</p>
<p>An Analysis report by DefenceIntelligence  <a title="Analysis" href="http://defintel.com/docs/Mariposa_Analysis.pdf">here </a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/mariposa-botnet-another-financial-botnet-that-infected-12-7-computer/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cracking Down on Botnets &#8211;  Microsoft  against Waledac</title>
		<link>http://www.honeynet.it/botnet/the-official-microsoft-blog-%e2%80%93-news-and-perspectives-from-microsoft-cracking-down-on-botnets</link>
		<comments>http://www.honeynet.it/botnet/the-official-microsoft-blog-%e2%80%93-news-and-perspectives-from-microsoft-cracking-down-on-botnets#comments</comments>
		<pubDate>Thu, 25 Feb 2010 20:15:36 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Botnet 2.0]]></category>
		<category><![CDATA[Media]]></category>
		<category><![CDATA[Press]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[P2P]]></category>
		<category><![CDATA[waledac]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=176</guid>
		<description><![CDATA[
The takedown of the Waledac botnet that Microsoft executed this week – known internally as “Operation b49” – was the result of months of investigation and the innovative application of a tried and true legal strategy. [..] In a recent analysis, Microsoft found that between December 3-21, 2009, approximately 651 million spam emails attributable to [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>The takedown of the Waledac botnet that Microsoft executed this week – known internally as “Operation b49” – was the result of months of investigation and the innovative application of a tried and true legal strategy.</p>
<p>[..]</p>
<p>In a recent analysis, Microsoft found that between December 3-21, 2009, approximately 651 million spam emails attributable to Waledac were directed to Hotmail accounts alone, including offers and scams related to online pharmacies, imitation goods, jobs, penny stocks and more.</p>
<p>[..]</p>
<p>This action has quickly and effectively cut off traffic to Waledac at the “.com” or domain registry level, severing the connection between the command and control centers of the botnet and most of its thousands of zombie computers around the world.</p></blockquote>
<p>via <a href="http://blogs.technet.com/microsoft_blog/archive/2010/02/25/cracking-down-on-botnets.aspx">The Official Microsoft Blog – Cracking Down on Botnets</a>.</p>
<p>Well done.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/the-official-microsoft-blog-%e2%80%93-news-and-perspectives-from-microsoft-cracking-down-on-botnets/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

