On CBS MoneyWatch: The Dumbest Generation: Who Is It?
BNET Business Network:
BNET
TechRepublic
ZDNet

By Tom Espiner , ZDNet (UK)
Posted on ZDNet News: Nov 9, 2007 11:53:00 AM

A Russian gang allegedly hosting malicious software abruptly disappeared this week, according to Trend Micro.

The Russian Business Network, which allegedly was heavily involved in hosting packing kits--development suites for malicious software--suddenly dropped off the Internet on Tuesday, the Tokyo-based security company said.

"It feels like their upstream providers put them on a blacklist and terminated services to this problematic customer," Raimund Genes, chief technology officer of Trend Micro's antivirus division, said Friday.

Researchers from Internet security company VeriSign said RBN has been able to offer "bulletproof hosting" for malicious software by means of links to the Russian government.

Genes claimed it is likely that whatever protection RBN enjoyed was withdrawn because the group had overreached itself. "All kinds of cybercrime was on RBN sites, but recently, they've become too greedy," Genes said. "They infiltrated a Turkish government site so that it pointed to a site in Panama that was registered under RBN. (The site) was rented to multiple malware gangs."

Genes added that some U.S. government and Brazilian sites, which he declined to identify specifically, had been compromised through SQL (Structured Query Language) injection attacks to make them point to other RBN sites compromised with malicious software. "Maybe some government was upset by (RBN) activity," Genes said.

Although Trend Micro says it cannot be 100 percent sure, the company believes that the gang has shifted operations to Asia. Sites hosted in Taiwan and China are now hosting malicious-software packing kits and software that had been commonly hosted on RBN sites.

"Sites in Taiwan and China are now hosting malware with the same behavior," Genes said. "MPack (packer kit) and its IcePack add-on are being offered, as well as iframe exploits."

MPack is a PHP-based kit that allows its developers to sell modules of malicious code. So-called iframe is an HTML tag that allows the embedding of a Web page inside another document; iframe malicious software targets Web browsers by attacking vulnerabilities in the way they handle iframe HTML tags.

Tom Espiner of ZDNet UK reported from London.

©2007 CNET Networks, Inc. All rights reserved. CNET , CNET.com , and the CNET logo are registered trademarks of CNET Networks, Inc. Used by permission.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 12 Talkback(s)
Where there is enough money to be made...
...someone will take the risks to make it. Spam, porn, 'cheap' drugs for sale, credit card/identity theft... they are all very profitable and will draw greedy people to replace the RBN. Just like tak... (Read the rest)
Posted by: jlrobins Posted on: 12/06/07 You are currently: a Guest | | Terms of Use
Hunt Them Down And Terminate Them  John Westra | 11/10/07
Safe in China  DarthRidiculous | 11/11/07
In China  jswift | 11/12/07
"legitimate" companies too?  roberto_maietta@... | 11/12/07
These companies are the lifeblood of innovation  1stcyberian | 11/12/07
innovation is ok - crime is not  Charlie2811@... | 11/12/07
If you only look at the bare statistics...  Raymond Danner | 11/12/07
Let's look at some facts...  reholli@... | 11/12/07
You need to find a source of fresh air...  Media-Ted@... | 11/15/07
These people are a plague  Tom in Toronto | 11/13/07
It's like the pirates  John Musbach | 11/13/07
Where there is enough money to be made...  jlrobins | 12/06/07

What do you think?

advertisement
advertisement
Click Here

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here