Related Links

Related Stories

  • Zero Day of the Dead
    The data load that has accompanied the globalization of trade would make even Atlas stagger. And that’s without the added burden of counter-terrorisAs you read this, zombie programs are flitting across the internet like a pestilence to infect and drain the life from innocent computer systems. Yet, for all the aggravation and grief they cause, you may never know you are part of a global invasion of the system snatchers, says William Knight. Unless…
  • Search for security
    With more than 30 000 web pages being infected every day, search engine results could increasingly lead to malware infection. Kari Larsen asks what the search engines are doing to mitigate security threats, and how users can protect themselves.
  • China preparing to ramp up cyberespionage?
    A report commissioned by a US Congressional advisory panel monitoring the security implications of trading with China has warned that China could be preparing to ramp up cyberespionage and has started spying on the servers of the US government and major companies.
  • Nine lives - when malware becomes self-modifying
    As the Conficker (aka Downadup and Kido) worm proved when it first appeared in October 2008, there's more to a piece of malware code than meets the eye, especially when it is self-updating. But can self-updating also mean self-modifying? Steve Gold investigates whether an IT security manager's nightmare has become programming reality...
  • Google launches Anti-Malvertising.com site
    Google have launched Anti-Malvertising.com to assist its advertisers in spotting potential providers of malicious advertisements. Finjan, specialising in secure web gateway products and unified web security for the enterprise market,have welcomed this launch.

News

GoldenCashWorld botnet, malware and hacker data exchange portal revealed

17 June 2009

Security researchers with Finjan have uncovered a highly sophisticated online botnet, malware and hacker exchange network for buying and selling access to infected PCs.

The business Internet security vendor says that this raises concerns that businesses, governments and even home computer users are growing even more vulnerable to cybercrime.

Known as GoldenCashWorld, the botnet-driven network and website acts as a one-stop shop for people who seek to acquire, sell or trade infected computers and even entire websites.

According to the researchers, infected PCs can be used to send spam, collect documents and personal information or inject new websites with malware that can then be passed on to fresh PCs.

Infosecurity understands that GoldenCashWorld includes tools for creating malicious code and stolen credentials for around 100 000 websites.

Although the focus of the botnet, malware and hacker network appears to be in Russia, about 40% of the compromised PCs on network actually belong to individuals or companies in the US.

"This is the most advanced network we've found", says Yuval Ben-Itzhak, Finjan's chief technology officer.

"They're trying to combine all the elements together and enable more people to participate in this crime."

Infosecurity notes that the GoldenCashWorld website - which was first uncovered by Finjan around two months ago - is surrounded by proxy servers to disguise the site's real address.

Although this technique is used by some organisations to make life difficult for hackers wanting to stage a distributed denial of service (DDoS) attack, this is one of the first times the approach has been used to disguise a hacker site.

GoldenCashWorld also has an affiliate marketing programme to encourage third parties to link to the site and its services.

Ben-Itzhak says that the site highlights the fact that cybercriminals are always looking for improved methods to generate new and extra profit.

 

This article is featured in:
Internet and Network Security Malware and Hardware Security

 

Comment on this article

You must be registered and logged in to leave a comment about this article.