Zeus (Kneber) Botnet Infection is bad for business

newsguy 0 Tallied Votes 979 Views Share

Botnets are bad for business, and that's the bottom line. The news that a botnet called Kneber has infected 75,000 computers including government and business machines has been spreading online. But while many, if not most, of these reports are claiming that Kneber is a new botnet the truth is that actually it is nothing of the sort. Not that the revelation that Kneber is actually just another Zeus variation will be of any comfort to those who have fallen victim to the thing, of course. Victims such as, according to security outfit NetWitness which first reported the outbreak, the 68,000 stolen corporate logins for example, or the 2000 SSL certificate files, or how about the "dossier-level data sets on individuals including complete dumps of entire identities from victim machines" for that matter.

"The reason some folks have nicknamed it Kneber is that the malware domains involved in this particular branch of the Zeus botnet have “Hilary Kneber” listed as the domain registrant. Of course, Hilary Kneber is likely a completely made-up name" Mary Landesman, senior security researcher at ScanSafe. The Zeus botnet has been active on the Web for over a year. In its 1Q08 Global Threat Report, ScanSafe reported on the surge of Zeus-related activity via the Web and specifically it’s joining forces with the LuckySploit framework. Zeus malware is known for browser traffic sniffing, intercepting POST data and keystrokes associated with the active browser session, as well as clipboard data passed to the browser. Worryingly, Zeus malware also typically disables firewalls and other security software on infected systems, as well as blocking access to security vendor websites and services. For example, Zeus can prevent antivirus signatures from being updated putting companies at major risk of infection. Zeus Trojans also employ rootkits to remain hidden on infected systems.

Whatever you call it, this botnet is bad for business. In 2009, for example, malware associated with Zeus alone accounted for one percent of all the ScanSafe Web malware blocks during the year.

Discussing the importance of the "Kneber botnet" Amit Yoran, CEO of NetWitness and former Director of the National Cyber Security Division, , "While Operation Aurora shed light on advanced threats from sponsored adversaries, the number of compromised companies and organizations pales in comparison to this single botnet. These large-scale compromises of enterprise networks have reached epidemic levels. Cyber criminal elements, like the Kneber crew quietly and diligently target and compromise thousands of government and commercial organizations across the globe. Conventional malware protection and signature based intrusion detection systems are by definition inadequate for addressing Kneber or most other advanced threats. Organizations which focus on compliance as the objective of their information security programs and have not kept pace with the rapid advances of the threat environment will not see this Trojan until the damage already has occurred. Systems compromised by this botnet provide the attackers not only user credentials and confidential information, but remote access inside the compromised networks".

Dani AI

Generated

As pointed out, this Kneber/Zeus event is the kind of incident that should be handled as a full compromise — not a one-off malware removal. Treat credentials, certificate material, and any systems with elevated access as potentially exposed. Preserve evidence first; respond on a planed IR timeline rather than by ad-hoc cleanup.

  • Isolate suspected hosts from the network but do not destroy volatile evidence. Capture memory and image disks before reimaging when practical.
  • Gather logs immediately: firewall, proxy, DNS, VPN, domain controllers and any endpoint telemetry (EDR/Sysmon). Correlate authentication events and unusual lateral logons to determine scope.
  • Contain access: disable or rotate service and privileged credentials from a known-clean machine or out-of-band system. Revoke and reissue any SSL/TLS certificates if private keys may have been stored on endpoints.
  • Remediate endpoints by rebuilding from trusted images; avoid simple AV cleanup on machines that were clearly breached. Confirm hosts are clean with behavior-based tools before returning to production.
  • Strengthen detection: deploy or tune behavioral EDR, centralize logs, enable DNS/NetFlow monitoring and periodic threat hunts for unusual outbound channels. Add MFA and least-privilege controls for high-risk accounts.
  • If compromise is broad, engage experienced incident responders and involve legal/compliance for notification and preservation of chain of custody.

This incident is a reminder that signature updates alone are not enough. Prioritize containment, evidence preservation, credential recovery from clean systems, and tighter controls that reduce blast radius going forward.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.