Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Virus alerts

February 15th, 2012, 15:39 GMT · By Eduard Kovacs

Waledac Botnet Returns, Steals Passwords and Credentials

SHARE:

Adjust text size:


Palo Alto discovered a new variant of the Waledac botnet
Enlarge picture
In 2010 Microsoft was able to terminate the activity of the Waledac botnet, which at the time was famous for being a large source of spam. However, Palo Alto Networks researchers came across a new variant of the botnet which is not used only for spamming, but also for stealing sensitive data from the infected devices.

The new version of Waledac was spotted on February 2 and experts have been analyzing it ever since. They conclude that it’s still sending spam, but it can also steal passwords and authentication data, including credentials for FTP, POP3, SMTP.

Besides this, Waledac also steals .dat files for FTP and BitCoin and uploads them to the botnet.

By relying on their WildFire systems, which enable a firewall to capture unknown files and analyze them in a malware sandbox, Palo Alto Networks were able to identify how the new variant behaves.

Given the confusion that was created around the Kelihos botnet which was declared resurrected by Kaspersky, only to be put to sleep again by Microsoft, the company emphasizes the fact that this is not the old botnet, but a new variant.

Symantec also covered the emergence of the new botnet. The security solutions provider spotted it at doing what it accustomed us to: spamming.

An email that targeted only Russian users served a website called Rospress which promoted slanderous articles, but it was uncertain if the purpose was to smudge the upcoming Russian elections or merely to advertise the site.

“While it is not clear whether the intent of this Waledac spam campaign has been to promote the Rospres.com site or to smear the election campaign of any individual, it does question the exact motivation of the malware gang controlling the W32.Waledac.C variant,” Symantec experts said.
FILED UNDER:
Waledac
botnet
spam

TELL US WHAT YOU THINK:

1,484 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Anonymous DDOS Attacks Explained by Expert (Exclusive)

Citadel Trojan May Be Improved with Mini-Antivirus

Kelihos Not Resurrected, New Malware Used to Create Botnet

With Masters Still at Large, the Kelihos Botnet Returns

New ZeuS Variant ‘Citadel’ Comes with Customer Support

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM