- 10 Microsoft research projects
- 10 kitchen gadgets for the geek gourmet
- Verizon trounces competition
- Smartphone smackdown: Storm vs. iPhone
- FBI warns of holiday cyber scams
The 46,000 people reportedly infected by ads on job sites may be only a fraction of the victims of an ambitious, multi-stage attack that's stolen data belonging to several hundred thousand people who posted resumes on Monster.com, a researcher said this weekend.
According to Symantec Security Analyst Amado Hidalgo, a new Trojan horse the company calls Infostealer.Monstres has stolen more than 1.6 million records belonging to several hundred thousand people from the job search service Monster.com. That data is then used to target the Monster.com users with credible phishing mail that plants more malware on their machines.
"We are investigating the reports related to this Trojan and will take any necessary steps indicated by that investigation," Monster.com spokesman Steve Sylven said Sunday in an e-mail.
The personal information filched from Monster.com includes names, e-mail addresses, home address, phone numbers, and resume ID number, said Hidalgo, who traced the data to a remote server used by the attackers to store the stolen information. Infostealer.Monstres ripped off Monster.com by using legitimate log-ons, likely stolen from recruiters and human resource personnel who have access to the "Monster for employers" areas of the site. Once inside, the Trojan ran automated searches for resumes of candidates located in certain countries or working in certain fields. The results were then uploaded to the attackers' remote server.
"Such a large database of highly personal information is a spammer's dream," said Hidalgo. In fact, that's exactly what the attackers are using their newly-acquired data for.
"The attackers first gather e-mail address and other personal information from resumes posted to Monster.com with Infostealer.Monstres," Hidalgo said. "Next, they will try to infect the computers of those candidates by sending targeted Monster.com phishing mails which install [Banker.c or Gpcoder.e]."
The first piece of malware, dubbed Banker.c by Symantec, is a run-of-the-mill information-stealing Trojan that monitors the infected PC for log-ons to online banking accounts; when it sniffs a log-on in process, Banker.c records the username and password, then transmits the data back to hacker HQ. Gpcoder.e, on the other hand, is "ransomware," the name given to Trojans which encrypt files on the hacked computer, then hold those files hostage until the user pays a fee to unlock the data.
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comments (1)
RE: Identity attack spreads; 1.6M records stolen from Monster.comBy rodney boone on August 21, 2007, 9:47 amNEAT
Reply | Read entire comment
View all comments