Recent Bank of India hack done by Russians

Sep 4, 2007 09:06 GMT  ·  By

The Russian Business Network: many of you have heard about it and about all the bad stuff related to it. But for those of you who don't know, let me tell you that RBN is a sort of ghost Internet service provider (ISP). They are not registered anywhere and there are no official records of this network. There are 2 things that are known about it - first, that it hosts a lot of nasty stuff and the second is that its leaders have some high connections in St. Petersburg.

They are the ones to blame for the attack on the Bank of India, a fact which has been stated by none other than Sunbelt, the security firm that earlier discovered the hack. The bank's official site was filled with all sorts of malware, but mainly info-stealing trojans.

In any case, all that the RBN hosts is illegal and there is no server under their command that doesn't have phished data, malicious code, botnet command and control, denial-of-service attack traces and child porn on it, as I've read on ZDNet. These guys are bad, but I guess everyone already knew that, but what might have eluded you is the fact that their "business" is to attack non-Russian financial institutions. I wonder if any of these attacks are Russian-official ordered...

They have also been said to be related to the Mpack Group. Mpack is one of the top programs any black hat hacker would love to have. This malware is said to have many features but it is mainly used for the theft of confidential data.

So let's see, they phish, hack, host child porn and do a lot of illegal things, but nobody can do anything to them because of their high connections. Could it get worse? Hardly!