<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Italian Honey Project &#187; zeus</title>
	<atom:link href="http://www.honeynet.it/tag/zeus/feed" rel="self" type="application/rss+xml" />
	<link>http://www.honeynet.it</link>
	<description>The Italian chapter of the Honeynet Research Alliance</description>
	<lastBuildDate>Tue, 10 Aug 2010 12:54:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Zbot authors forge Kaspersky Digital Signature</title>
		<link>http://www.honeynet.it/botnet/zbot-authors-forge-kaspersky-digital-signature</link>
		<comments>http://www.honeynet.it/botnet/zbot-authors-forge-kaspersky-digital-signature#comments</comments>
		<pubDate>Fri, 06 Aug 2010 07:43:00 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[zbot]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=333</guid>
		<description><![CDATA[
Security researchers warn that multiple recent Zbot variants are using a forged digital signature in an attempt to bypass antivurs detection. Ironically the digital signature was copied from a ZeuS removal tool developed by Kaspersky Lab. [..] There have been isolated cases of digitally-signed malware before, but the practice never really took off, primarily because [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>Security researchers warn that multiple recent Zbot variants are using a forged digital signature in an attempt to bypass antivurs detection. Ironically the digital signature was copied from a ZeuS removal tool developed by Kaspersky Lab.</p>
<p>[..]</p>
<p>There have been isolated cases of digitally-signed malware before, but the practice never really took off, primarily because malware authors believed the effort doesn&#8217;t justify the benefits.</p>
<p>[..]</p></blockquote>
<p>via <a href="http://news.softpedia.com/news/Zbot-Authors-Forge-Kaspersky-Digital-Signature-150817.shtml">Zbot Authors Forge Kaspersky Digital Signature &#8211; Copy it from ZeuZ removal tool &#8211; Softpedia</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/zbot-authors-forge-kaspersky-digital-signature/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Another Zeus botnet (100k bot) uncovered by Trusteer</title>
		<link>http://www.honeynet.it/botnet/another-zeus-botnet-100k-bot-uncovered-by-trusteer</link>
		<comments>http://www.honeynet.it/botnet/another-zeus-botnet-100k-bot-uncovered-by-trusteer#comments</comments>
		<pubDate>Wed, 04 Aug 2010 11:21:31 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=329</guid>
		<description><![CDATA[
Trusteer, the leading provider of secure browsing services, today announced that it has uncovered a large Zeus version 2 botnet being used to conduct financial fraud in the UK which is operated and controlled from Eastern Europe. The botnet appears to be controlling more than 100,000 infected computers, 98% of which are UK Internet users. [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>Trusteer, the leading provider of secure browsing services, today announced that it has uncovered a large Zeus version 2 botnet being used to conduct financial fraud in the UK which is operated and controlled from Eastern Europe. The botnet appears to be controlling more than 100,000 infected computers, 98% of which are UK Internet users.</p></blockquote>
<p>via <a href="http://www.tmcnet.com/usubmit/-trusteer-trusteer-uncovers-zeus-botnet-that-plunders-over-/2010/08/03/4937294.htm">Trusteer: Trusteer uncovers Zeus botnet that plunders over 100,000 UK Internet user credentials</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/another-zeus-botnet-100k-bot-uncovered-by-trusteer/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Zeus affiliated botnet discovered by AVG : &#8220;Mumba&#8221;</title>
		<link>http://www.honeynet.it/botnet/new-zeus-affiliated-botnet-discovered-by-avg-mumba</link>
		<comments>http://www.honeynet.it/botnet/new-zeus-affiliated-botnet-discovered-by-avg-mumba#comments</comments>
		<pubDate>Tue, 03 Aug 2010 10:41:57 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[mumba]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=327</guid>
		<description><![CDATA[
According to a newly published report by AVG, upon obtaining access to a mini ZeuS botnet dubbed Mumba, part of Avalanche group’s online operations, they found 60GB of stolen data such as, accounting details for social networking sites, banking accounts, credit card numbers and intercepted emails. via Researchers peek inside a mini ZeuS botnet, find [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>According to a newly published report by <a href="http://thompson.blog.avg.com/2010/08/todays-battle-with-cyber-criminals-is-a-bit-like-the-old-fashioned-cops-and-robbers-stories-of-years-agothe-police-were-cons.html" target="_blank">AVG</a>, upon obtaining access to a mini ZeuS botnet dubbed <a href="http://avg.typepad.com/files/revised-mumba-botnet-whitepaper_approved_yi_fv.pdf" target="_blank">Mumba</a>, part of Avalanche group’s online operations, they found 60GB of stolen data such as, accounting details for social networking sites, banking accounts, credit card numbers and intercepted emails.</p></blockquote>
<p>via <a href="http://www.zdnet.com/blog/security/researchers-peek-inside-a-mini-zeus-botnet-find-60gb-of-stolen-data/7018?tag=mantle_skin;content">Researchers peek inside a mini ZeuS botnet, find 60GB of stolen data | ZDNet</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/new-zeus-affiliated-botnet-discovered-by-avg-mumba/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Big Boss operation : Check Counterfeiting Ring &#8211; by SecureWorks</title>
		<link>http://www.honeynet.it/botnet/big-boss-operation-check-counterfeiting-ring-by-secureworks</link>
		<comments>http://www.honeynet.it/botnet/big-boss-operation-check-counterfeiting-ring-by-secureworks#comments</comments>
		<pubDate>Tue, 03 Aug 2010 10:35:08 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[Counterfeiting]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=325</guid>
		<description><![CDATA[
Three-month-long investigation by CTU uncovers inner workings of Russian check counterfeiting operation. SecureWorks has notified and is working with law enforcement on this scam. SecureWorks has protections in place for both the Zeus and the Gozi Trojans which are utilized in this scam. via Big Boss Check Counterfeiting Ring &#8211; Research &#8211; SecureWorks.
]]></description>
			<content:encoded><![CDATA[<blockquote><p>Three-month-long investigation by CTU uncovers inner workings of Russian check counterfeiting operation. SecureWorks has notified and is working with law enforcement on this scam.  SecureWorks has protections in place for both the Zeus and the Gozi Trojans which are utilized in this scam.</p></blockquote>
<p>via <a href="http://www.secureworks.com/research/threats/big-boss/?threat=big-boss">Big Boss Check Counterfeiting Ring &#8211; Research &#8211; SecureWorks</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/big-boss-operation-check-counterfeiting-ring-by-secureworks/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Zbot variant discovered</title>
		<link>http://www.honeynet.it/botnet/new-zbot-variant-discovered</link>
		<comments>http://www.honeynet.it/botnet/new-zbot-variant-discovered#comments</comments>
		<pubDate>Thu, 29 Jul 2010 12:39:45 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=320</guid>
		<description><![CDATA[
SecureWorks researchers uncovered the complicated operation in April when it discovered a unique variant of the well-known Zeus Trojan that targets Windows-based PCs. In addition to stealing login credentials, the Trojan established a virtual private network VPN connection from the infected computer to a remote server using the PPTP Point-to-Point Tunneling Protocol functionality in Windows [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>SecureWorks researchers uncovered the complicated operation in April when it discovered a unique variant of the well-known Zeus Trojan that targets Windows-based PCs. In addition to stealing login credentials, the Trojan established a virtual private network VPN connection from the infected computer to a remote server using the PPTP Point-to-Point Tunneling Protocol functionality in Windows and listened to a random TCP Transmission Control Protocol port in order to serve as a SOCKS proxy.</p></blockquote>
<p>via <a href="http://news.cnet.com/8301-27080_3-20011885-245.html">Check counterfeiting using botnets and money mules | InSecurity Complex &#8211; CNET News</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/new-zbot-variant-discovered/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Top US banks targeted by Mastercard and Visa scam</title>
		<link>http://www.honeynet.it/botnet/top-us-banks-targeted-by-mastercard-and-visa-scam</link>
		<comments>http://www.honeynet.it/botnet/top-us-banks-targeted-by-mastercard-and-visa-scam#comments</comments>
		<pubDate>Thu, 15 Jul 2010 09:19:36 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[mastercard]]></category>
		<category><![CDATA[visa]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=309</guid>
		<description><![CDATA[
Hackers have managed to copy the Verified by Visa and MasterCard SecureCode protection features in order to dupe customers at 15 top US banks, a security firm has warned. via Top US banks targeted by Mastercard and Visa scam &#124; IT PRO.
]]></description>
			<content:encoded><![CDATA[<blockquote><p>Hackers have managed to copy the Verified by Visa and MasterCard SecureCode protection features in order to dupe customers at 15 top US banks, a security firm has warned.</p></blockquote>
<p>via <a href="http://www.itpro.co.uk/625168/top-us-banks-targeted-by-mastercard-and-visa-scam">Top US banks targeted by Mastercard and Visa scam | IT PRO</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/top-us-banks-targeted-by-mastercard-and-visa-scam/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Zeus Version 3 – Hit Spain 26%, UK 22% , USA 19%</title>
		<link>http://www.honeynet.it/botnet/zeus-version-3-%e2%80%93-hit-spain-26-uk-22-usa-19</link>
		<comments>http://www.honeynet.it/botnet/zeus-version-3-%e2%80%93-hit-spain-26-uk-22-usa-19#comments</comments>
		<pubDate>Tue, 13 Jul 2010 11:34:32 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=307</guid>
		<description><![CDATA[
The latest Zeus bot configuration contains list of targeted financial institution from Spain, Germany, United Kingdom, and USA. The previous versions contains all the list of financial institutions from different countries around the world, while the new version only contains two targeted countries and currently paired as: Spain-Germany and UK-USA via Zeus Version 3 – [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>The latest Zeus bot configuration contains list of targeted financial institution from Spain, Germany, United Kingdom, and USA. The previous versions contains all the list of financial institutions from different countries around the world, while the new version only contains two targeted countries and currently paired as: Spain-Germany and UK-USA</p></blockquote>
<p>via <a href="http://community.ca.com/blogs/securityadvisor/archive/2010/07/12/zeus-version-3-target-spain-germany-uk-and-usa-banks.aspx">Zeus Version 3 – Target Spain, Germany, UK, and USA Banks &#8211; CA Security Advisor Research Blog</a>.</p>
<p>According to CA , Spanish financial institutions appears to be the most targeted (26%) by this new version of ZBot.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/zeus-version-3-%e2%80%93-hit-spain-26-uk-22-usa-19/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Zeus bot targets Russian Banks</title>
		<link>http://www.honeynet.it/botnet/new-zeus-bot-targets-russian-banks</link>
		<comments>http://www.honeynet.it/botnet/new-zeus-bot-targets-russian-banks#comments</comments>
		<pubDate>Wed, 07 Jul 2010 08:02:21 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=291</guid>
		<description><![CDATA[
This is the first time I’ve seen ZeuS target Russian banks given that online banking is not so popular in Russia. I can recall a few ZeuS/ZBOT samples targeting Yandex services, but I definitely can’t recall anyone targeting MDM Bank or other online Russian banking systems. via ZeuS/ZBOT Targets Russian Banks &#124; Malware Blog &#124; [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>This is the first time I’ve seen ZeuS target Russian banks given that online banking is not so popular in Russia. I can recall a few ZeuS/ZBOT samples targeting Yandex services, but I definitely can’t recall anyone targeting MDM Bank or other online Russian banking systems.</p></blockquote>
<p>via <a href="http://blog.trendmicro.com/zeuszbot-targets-russian-banks/">ZeuS/ZBOT Targets Russian Banks | Malware Blog | Trend Micro</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/new-zeus-bot-targets-russian-banks/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Zeus-friendly ISP taken down</title>
		<link>http://www.honeynet.it/botnet/zeus-friendly-isp-taken-down</link>
		<comments>http://www.honeynet.it/botnet/zeus-friendly-isp-taken-down#comments</comments>
		<pubDate>Tue, 18 May 2010 07:50:42 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Press]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=258</guid>
		<description><![CDATA[
The latest in the string of &#8220;bulletproof&#8221; ISPs has been taken down on Friday after its upstream service provider DIGERNET has been disconnected. PROXIEZ-NET went down making its claims of being immune to shutdowns untrue. According to The Register just days before the shutdown PROXIEZ-NET found its way to the Spamhaus block list for &#8220;acting [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>The latest in the string of &#8220;bulletproof&#8221; ISPs has been taken down on Friday  after its upstream service provider  DIGERNET  has been disconnected.    PROXIEZ-NET went down  making its claims of being immune to shutdowns untrue. According to The Register  just days before the shutdown  PROXIEZ-NET found its way to the Spamhaus  block list for &#8220;acting as a ZeuS botnet C&amp;C or hosting binaries dropzones for the ZeuS botnet.&#8221;</p></blockquote>
<p>via <a href="http://www.net-security.org/malware_news.php?id=1343">Zeus-friendly ISP taken down</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/zeus-friendly-isp-taken-down/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>At a Glance: New ZeuS Variants</title>
		<link>http://www.honeynet.it/botnet/at-a-glance-new-zeus-variants</link>
		<comments>http://www.honeynet.it/botnet/at-a-glance-new-zeus-variants#comments</comments>
		<pubDate>Tue, 27 Apr 2010 16:28:15 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=244</guid>
		<description><![CDATA[
This time, the malware upholds it notorious reputation with a new version related to previous detections TSPY_ZBOT.CRM and TSPY_ZBOT.CQJ. ZBOT variants steal account credentials when users visit various social networking, online shopping, and bank-related websites. They have rapidly become popular tools for cybercriminals to use, thanks to exceptional information-stealing routines and rootkit capabilities, which allows [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>This time, the malware upholds it notorious reputation with a new version related to previous detections TSPY_ZBOT.CRM and TSPY_ZBOT.CQJ.</p></blockquote>
<blockquote><p>ZBOT variants steal account credentials when users visit various social networking, online shopping, and bank-related websites. They have rapidly become popular tools for cybercriminals to use, thanks to exceptional information-stealing routines and rootkit capabilities, which allows them to stay stealthy and to affect users’ systems without their knowledge.</p></blockquote>
<p>via <a href="http://blog.trendmicro.com/at-a-glance-new-zeus-variants/">Trend Micro</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/at-a-glance-new-zeus-variants/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
