TMCnet News

Aladdin Study: Latest eBay Botnet Attack Targets UK Consumers
[September 07, 2007]

Aladdin Study: Latest eBay Botnet Attack Targets UK Consumers


TMCnet Contributing Editor
 
Aladdin eSafe Content Security Response Team (CSRT) of Aladdin Knowledge Systems has said it uncovered significant new details surrounding the eBay (News - Alert) botnet attack when it discovered it for the first time on September 3rd.
 
The security response team that analyzed the phishing attacks noted that UK eBay accounts are more vulnerable to such attacks. The team said that the latest attack was first of its kind to employ extremely complex, multi-stage attack methods. The attackers have applied a distributed and covert brute force on eBay accounts in an effort to obtain personal information as well as their transaction details on eBay's site, Aladdin said in a statement to press. 

 
In many instances, victims entered their credentials in phishing sites controlled by the attackers and gave further opportunity for the attackers to quickly gain access to an even larger number of accounts, Aladdin said. Aladdin CSRT has validated cases in which the botnet collected active eBay account details. Even though the attacks were targeted more on UK accounts, the Trojans appear to have the ability to distinguish US accounts from non-US accounts.

"Through new infection and attack methods, this targeted threat shows that Trojans are continuing to evolve into extremely dynamic, adaptive tools for online criminals, resulting in a potentially damaging aftermath for its individual victims," said Ofer Elzam, director of product management for the Aladdin eSafe Business Unit and head of the Aladdin eSafe CSRT in a statement to the press. "This eBay botnet attack is unique, and definitely not found through traditional security measures. Aladdin's innovative security specialists are closely monitoring this new threat and are notifying the Web sites we determine are infecting Web surfers."

As per the discovery of Aladdin eSafe CSRT, the modus operandi of the crooks is to use a sophisticated Trojan first to infect the hacked websites worldwide and then use the infected computers to conduct a further sophisticated distributed attack on eBay accounts.
  
The operation of the attackers alters settings that can place sold items in the wrong hands. Aladdin researchers estimated that the threat has gone undetected for several days and that the Trojans might still be continuing to affect visitors.
 
P.R. Sai is a contributing writer for TMCnet. To see more of his articles, please visit his columnist page.
 

[ Back To TMCnet.com's Homepage ]