News & Information for Technology Purchasers
NewsFactor Network Sites:   NewsFactor.com Security CRM Business Sci-Tech Newsletters XML/RSS Feed  
   
Home Enterprise I.T. Hardware Software Communications More Topics...
Data Security
Average Rating:
Rate this article:  
Clampi Worm Puts Online Financial Transactions at Risk Clampi Worm Puts Online Financial Transactions at Risk
By Jennifer LeClaire
July 31, 2009 10:42AM

    Bookmark and Share
An older worm known as Clampi and other names is gaining momentum across the Web and stealing financial credentials on Microsoft networks. Joe Stewart of SecureWorks said the Clampi Trojan is using domain-administrator tools to spread. Ken Dunham of iSight Partners said malware codes are now incredibly sophisticated.
 

Advertisement

With security Relevant Products/Services researchers focused on the Black Hat security conference, a Trojan called Clampi is still making its way across the Web looking for victims.

Also known as Ligats, Ilomo or Rscan, Clampi is a Trojan that aims to steal credentials from infected systems. According to SecureWorks, hundreds of thousands of Windows computers may already be infected and many more are at risk. In one recent example, an auto-parts store lost about $75,000 to a group of attackers leveraging the power of Clamp in early July.

Although Clampi is not a new threat -- it has been harassing Windows users since 2007 -- security researchers report it is gaining momentum.

Joe Stewart, SecureWorks director of malware research for the counter threat unit, launched an in-depth investigation into the Trojan and its use of the psexec tools to spread earlier this year. What he discovered is troubling.

"In recent months, Clampi has successfully spread across Microsoft Relevant Products/Services networks in a worm-like fashion," Stewart said.

How Clampi Attacks

Stewart has identified 1,400 of the 4,500 Web sites in 70 different countries Clampi attackers are targeting. The Clampi Trojan, he reported, requests information specifically from these sites via infected computers. A sophisticated organized-crime group from Eastern Europe is running Clampi and has been implicated in numerous high-dollar thefts from banking institutions.

"Clampi's recent success in infecting victims is accomplished by using domain-administrator credentials -- either stolen by the Trojan or reused, or by virtue of the fact that a domain administrator has logged into an already infected system. Once domain-administrator privileges are granted, the Trojan uses the SysInternals tool psexec to copy itself to all computers on the domain," Stewart said. "Clampi also serves as a proxy server Relevant Products/Services used by criminals to anonymize their activity when logging into stolen accounts."

Although most major antivirus engines should detect Clampi and its variants, Stewart said there is always a delay between a new Trojan release and the detection time. He recommends businesses that use online banking and financial transactions adopt a strategy to isolate workstations where these activities are carried out.

Sophisticated Risks

Today's malware codes are incredibly sophisticated -- and may even have their own internal encryption capabilities to hinder analysis or hijacking of their botnets or codes, according to Ken Dunham, director of global response at iSight Partners.

"Even if you wipe Windows and reinstall it, many of these Trojans can still load up and take control of your system. We're moving toward disk-level- or hardware-level-based compromise," Dunham said. "The sophistication is something that needs to be recognized. We're dealing with highly organized, talented people that are criminals."

Best practices are a must, but it can be difficult to protect against Web-based attacks and specifically third-party browser attacks that leverage Flash and PDF. Dunham said he sees new reports of attacks that involve PDF or Flash exploits or something similar cross his desk every day.

"It's one thing to say you've got your Windows updated and your antivirus in place. It's another thing to say you've got your browser updated," Dunham said. "But do you have your browser plug-ins updated? It's complicated."
 

Advertisement


Advertisement


 Data Security
1.   Peer-to-Peer Software Ban Sought
2.   Los Alamos Computer Security Weak
3.   U.K. Police Make Trojan Virus Arrests
4.   Smartphones: New Security Risks
5.   FBI Says Hackers Targeting Law Firms


advertisement
Just How Secure Is Windows 7?Just How Secure Is Windows 7?
Sophos, Microsoft have different views.
Average Rating:
Vista More Secure Than Windows XPVista More Secure Than Windows XP
Windows 7 security could be expensive.
Average Rating:
Patch Tuesday Fixes Serious ThreatsPatch Tuesday Fixes Serious Threats
Three of six patches rated critical.
Average Rating:


advertisement
Product Information and Resources for Technology You Can Use To Boost Your Business

Enterprise Hardware

  Go Green with IBM Blade Center
  

Network Security Spotlight
House Lawmakers Push Ban on Peer-to-Peer Software
Stung by an embarrassing electronic leak revealing ethics investigations into dozens of lawmakers, Congress moved to prohibit federal employees from using the file-sharing software blamed for the disclosure.
 
GAO: Los Alamos Computer Security Has Weaknesses
Security weaknesses uncovered in Los Alamos National Laboratory's computer network increase the risk of a classified-information breach, says the Government Accountability Office.
 
Computer Security Firm Fortinet Plans IPO This Week
Fortinet plans to go public in an initial public offering, giving investors a chance to tap a network security provider with sales that are expected to grow. The IPO could be valued at $137.5 million or more.
 

Enterprise Hardware Spotlight
Flat Shipments Hurt Dell Despite Increased Earnings
Dell's earnings are up and expectations are solid, but the company's stock still took a hit after analysts signaled the company isn't playing a key role in the PC market recovery.
 
New Pogoplug 'Personal Cloud' Does Social Networking
Cloud Engines has released its newest version of the Pogoplug, a small "multimedia sharing device" that connects hard drives to the Internet and allows a user to access the files remotely.
 
Apple Tablet Rumored Delayed as Publisher Gears Up
There have been so many rumors of an Apple tablet that it has taken on legendary status. But now the legend is being revised with reports of a delay and that a major publisher is getting ready.
 

Enterprise Technology Spotlight
Flat Shipments Hurt Dell Despite Increased Earnings
Dell's earnings are up and expectations are solid, but the company's stock still took a hit after analysts signaled the company isn't playing a key role in the PC market recovery.
 
Smartphones: A Bigger Target for Security Threats
Smartphones are increasingly prevalent and adept at handling more tasks, including trading stocks, paying bills, and buying stuff online. That makes them attractive to thieves and hackers.
 
FBI Says Hackers Targeting Law Firms, PR Companies
Hackers are targeting law firms and public relations companies with a sophisticated e-mail scheme that breaks into their computer networks to steal sensitive data, often linked to large corporate clients.
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Hardware | Software | Communications | Network Security | Wireless Tech | Linux/Open Source
Apple/Macintosh | Microsoft/Windows | World Wide Web | Data Storage | E-Commerce | Personal Tech | Tech Trends | Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2009 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo.