Menu DaniWeb
Log In Sign Up
  • Read
  • Contribute
  • Meet
  1. Forums
  2. Hardware and Software
  3. Information Security
  4. News Stories
  5. News Story

Now Zeus 2 botnet adds client side cookie harvesting

16 Years Ago happygeek 0 Tallied Votes 518 Views Share

A new botnet has been discovered which is not only targeting users of UK banks, but doing so in a new and worrying manner. Said to comprise of in excess of 100,000 infected machines, the Zeus 2 botnet is operated and controlled from Eastern Europe according to secure browsing security provider Trusteer which went public with its discovery today.

Zeus botnets are sadly neither new or rare , however Amit Klein, Trusteer's Chief Technology Officer, reveals that this one is especially worrying as it doesn't just stop at harvesting user IDs and passwords but instead also looks for client side certificates and cookies. By doing this, Klein says "the cybercriminals can extract a lot of extra information on the user that can be used to augment their illegal access to those users' online accounts. Coupled with the ability to remotely control users' machines, download data and run any file on them, this means that the fraudsters can insert partial or complete Internet pages into a live Web session, enabling to inject transactions at will or extract even more data from the hapless victims".

Indeed, according to the Trusteer investigation it would seem that this particualr Zeus 2 botnet is harvesting anything and everything it can get its hands on, including: online account IDs, bank login information, credit and debit card numbers, account types and balances, bank statements, browser cookies, client side certificates, login information for email accounts and social networks, oh and not forgetting FTP passwords.

Trusteer was able to gain access to the botnet's drop servers and command and control center containing the stolen information which included hundreds of thousands of stolen credentials which effectively give the bad guys direct yet hidden access to the online financial activities of the compromised users.

Trusteer researchers also gained access to the management interface, allowing them to get a unique view into the methods used by the bad guys to control a Zeus botnet operation. The management interface itself can be thought of as enabling three main areas of functionality: the ability to monitor the growth and footprint of the botnet complete with detailed statistics and graphs, a search function on all traffic generated by the bots compiled by capturing all HTTP and HTTPS traffic from infected computers which is then stored in a central MySQL database, and finally a push update feature to send updated executables to specific bots.

Mickey Boodaei, Trusteer's CEO, says that the revelations surrounding the Zeus 2 botnet are the result of hundreds of man hours of effort behind the scenes by his security team, who constantly monitor for this type of activity. "Zeus has become one of the most prevalent botnet trojans in the history of online fraud" Boodaei said.

cybersecurity virus-malware
zeus.jpg 16.87 KB
About the Author
Member Avatar for happygeek
happygeek 2,411 Most Valuable Poster Team Colleague Featured Poster

A freelance technology journalist for 30 years, I have been a Contributing Editor at PC Pro (one of the best selling computer magazines in the UK) for most of them. As well as currently contributing to Forbes.com, The Times and Sunday Times via Raconteur…

Dani AI

Generated 9 Months Ago

Thread addendum referencing the original report and the follow-ups by , and with clear, practical steps for detection, cleanup and recovery.

Short checklist (what to do immediately): disconnect the suspected PC from the network (unplug Ethernet / disable Wi‑Fi), stop using it for banking or password changes, and preserve evidence only if you plan to do forensic analysis (image the drive first). Containment and evidence capture are standard incident‑response first steps; if recovery is a priority, treat the machine as compromised and isolate it. (itsupport.umd.edu)

Cleaning options and recommendation: a rescue/bootable scanner can remove many threats, but banking trojans often hide persistently — the safest path for a machine tied to financial accounts is to wipe and reimage (or replace the drive) and restore files from known‑good backups. When trying in‑place cleanup, run up‑to‑date, offline tools from trusted media (examples: Microsoft Safety Scanner or a vendor rescue disk), but accept that reinstallation is often the only way to be confident the box is clean. ’s instinct to reinstall is valid for a full recovery. (blogs.microsoft.com)

Account recovery and fraud steps: do not change bank or email passwords from the infected PC — use a different, known‑clean device. Immediately enable multi‑factor authentication where possible, contact banks/credit card companies to report suspected fraud, and follow the identity‑theft reporting/checklist recommended by consumer authorities. Monitor statements and consider fraud alerts or credit freezes if finances were exposed. (ftc.gov)

Hardening to avoid repeat infections: use a standard (non‑administrator) account for daily browsing, keep OS and browsers patched, use unique passwords with a manager, enable MFA and keep regular, offline backups. These changes reduce the attack surface and limit damage if an infostealer lands on a device. ()

Short, practical takeaway: assume compromise, isolate the system, recover accounts from a clean device, and prefer reimage for any machine used for banking.

Member Avatar for kp52
kp52 0 Newbie Poster
16 Years Ago

Useful to know this threat exists, but even more useful would be: what can we do to avoid it?

Member Avatar for Voidz
Voidz 0 Newbie Poster
15 Years Ago

Botnet's suck. I have one on my computer right now. Gotta reinstall Windows.

Reply to this topic
Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.

Sign Up — It's Free!
Recommended Topics
  • Member Avatar Malware hosting trends exposed 1
  • Member Avatar Virus - Programs hidden, malfunctioning 24
  • Member Avatar explorer.exe turns off automattically.. 1
  • Member Avatar Malware Help, Please >.< 37
  • Member Avatar How to destroy a botnet 0
  • Member Avatar Please help, Rundll.exe/iexplore.exe virus 1
  • Member Avatar Hijackthis logfile 4
  • Member Avatar search engine redirect virus 7
  • Member Avatar Internet Options won't open 1
  • Member Avatar WARNING: USB-based malware ignoring Windows AutoRun config 0
  • Member Avatar Spyware Problems 5
  • Member Avatar Who's Serving Up the Most Malware? Google 0
  • Member Avatar Trojan problem. Rustok-N 1
  • Member Avatar Google redirect virus 16
  • Member Avatar winbluesoft virus? Virus has a fake windows security icon on my taskbar 4
  • Member Avatar Google redirect virus 13
  • Member Avatar My highlighted stuff gets unhighlighted 7
  • Member Avatar ESET smart security v. 4.2.71.2 icon goes red and I can't fix it;( 7
  • Member Avatar Are these malware prgms legit? 32
  • Member Avatar URLsearchhook (na name) wont stay deleted, notsure if virus -PLEASE HELP 49
Not what you need?

Reach out to all the awesome people in our information security community by starting your own topic. We equally welcome both specific questions as well as open-ended discussions.

Start New Topic
Topics Feed
Reply to this Topic
Edit Preview

Share Post

Insert Code Block

  • Forums
  • Forum Index
  • Hardware & Software
  • Programming
  • Digital Media
  • Community Center
  • Recent
  • Recommended Topics
  • Newest Topics
  • Latest Topics
  • Latest Posts
  • Latest Comments
  • Top Tags
  • Tools
  • Writing
    • Start New Topic
    • Markdown Syntax
    • Newsletter Archive
  • Social
    • Top Members
    • Meet People
  • APIs
    • Connect API
    • Forum API Docs
    • Topics Feed
  • Resources
  • Community Rules
  • DaniWeb Premium
  • FAQ
  • About Us
  • Advertise
  • Contact Us
  • Legal
  • Terms of Service
  • Privacy Policy
© 2026 DaniWeb® LLC
© 2026 DaniWeb® LLC
  • FAQ
  • About Us
  • Advertise
  • Contact Us
  • Terms of Service
  • Privacy Policy