ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Infamous Russian malware gang vanishes

Tom Espiner ZDNet.co.uk

Published: 09 Nov 2007 18:08 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

An alleged Russian malware hosting gang has abruptly disappeared, according to Trend Micro.

The Russian Business Network (RBN), which was allegedly heavily involved in hosting malware packing kits — development suites for malware — suddenly dropped off the internet on Tuesday, said the security company.

"It feels like their upstream providers put them on a black list, and terminated services to this problematic customer," said Raimund Genes, chief technology officer for Trend Micro's antivirus division, on Friday.

Researchers from internet security company VeriSign said that RBN has been able to offer "bullet-proof hosting" for malware by means of links to the Russian government.

Genes claimed it is likely that whatever protection RBN enjoyed was withdrawn because the group had overreached itself. "All kinds of cybercrime was on RBN sites, but recently they've become too greedy," said Genes. "They infiltrated a Turkish government site so that it pointed to a site in Panama that was registered under RBN. [The site] was rented to multiple malware gangs."

Genes added that some US government and Brazilian sites, which he declined to identify specifically, had been compromised through SQL injection attacks to make them point to other RBN sites compromised with malware. "Maybe some government was upset by [RBN] activity," said Genes.

Although Trend Micro says it cannot be 100 percent sure, the company believes that the gang has shifted operations to Asia. Sites hosted in Taiwan and China are now hosting malware packing kits and malware which had been commonly hosted on RBN sites.

"Sites in Taiwan and China are now hosting malware with the same behaviour," said Genes. "MPack [packer kit] and its IcePack add-on are being offered, as well as Iframe exploits."

MPack is a PHP-based malware kit that allows its developers to sell modules of malicious code, while Iframe malware targets browsers by attacking vulnerabilities in the way they handle Iframe HTML tags.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
12 out of 12 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

Java / J2EE Developer - Government / Public Sector - 40 - 60k

The government practice works for major government departments and agencies across Central Government. IT consultancy based in Central London are ...

Lead Technician- Windows (MCP, MCSE, MCSA)

Engaging with their customers on a daily basis through phone, face to face, email and ticket contact, the Lead Technicians excel in creating ...

Project Manager (EDRMS / Local Government) required urgently

My Client, a Local Government Body based in Bournemouth is seeking a Project Manager to join their expanding team. As Project Manager you will be ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Biometric devices. Do you need one?

When saying “biometrics” I am not thinking about law enforcement, AFIS systems, national ID and visa projects. I first think about personal solutions that will make my life easier.... More

1 comment

Barracuda launches counter-suit agains...

Court cases are never pleasant or simple. The ongoing battle between security companies Trend Micro and Barracuda Networks took a new twist on Wednesday, when Barracuda launched a counter-suit... More

Post a comment

Mobile Speed Demon: Wireless Surpasses...

Mobile Speed Demon: Wireless Surpasses Landline Author: Eric Everson, Founder MyMobiSafe.com As I look around my house and throughout my network of friends, I instantly realize... More

Post a comment