FYI…

- http://www.informationweek.com/shared/prin…cleID=201202240
Aug. 1, 2007 - "A hacking tool for sale in the Russian underground is in the hands of 58 criminals who have infected more than 500,000 users, according to a security research firm. The MPack toolkit is a powerful exploitation tool that launches attacks against Web browsers. Ken Dunham, a senior engineer with VeriSign-iDefense reported this summer that the toolkit leverages multiple exploits – including the Windows ANI bug and a QuickTime overflow bug – to compromise computers. Finjan Software, Inc., a security company, reported this week that the malware being used within MPack is going after users' bank account information, such as user names, passwords, credit card numbers and Social Security numbers. And it's a highly successful tool, with an infection ratio of 16% of 3.1 million infection attempts. "The crimeware is capable of stealing account information from several banks around the world without leaving any traces behind," Finjan researchers reported in an advisory. "Stolen data is being sent to the criminals over a secure communication channel (SSL) to avoid detection. Users whose machines were infected by this crimeware will not notice any change to their normal PC and online browsing experience. The rootkit nature of the crimeware leaves no sign and does not impact the end-user experience." To make matters even worse for users and IT managers, the malware downloaded by the MPack toolkit is still not detected by the majority of popular security products, according to Finjan. And that makes it very effective in infecting PCs… the crimeware takes over the browser and creates a copy of the real banking page in real-time so the user is further tricked into thinking they're at a legitimate site. For each financial institution, the crimeware sends a customized set of crafted forms and pages, designed to harvest the specific information needed to log into that particular service. The crimeware is spread by compromised, legitimate sites that have malicious code embedded in them… VeriSign-iDefense also reported that attacks from MPack date back to October 2006."
> http://www.finjan.com/Pressrelease.aspx?id…=1230&lan=3
July 31, 2007

Related:
> http://isc.sans.org/diary.html?storyid=3015

:ph34r: