Saturday, August 27, 2005

Zotob Hackers Caught

The FBI has apprehended two men, who unleashed the Zotob worm. Farid Essebar from Morocco and Attilla Ecici from Turkey will be charged and prosecuted in their homelands for unleashing the Zotob worm.

Allegedly Essebar developed the code and sold it to Ecici.

Microsoft's Internet Crime Investigation Team is being credited for passing on a lot of information to the FBI, which resulted in the quick apprehension of the two suspects. This was accomplished by monitoring the attack in real time, which gave them the ability to follow the electronic trail back to it's source.

It's refreshing to see some quick action. The Microsoft Internet Investigation Team and the FBI deserve to be commended for their quick action and quality investigative work.

For a direct link to my original post and further links to worm removal products from Microsoft and Symantec, click on the title of this post.

Sunday, August 21, 2005

Attack of the Worms


In the past week, the mainstream news media has been awash with speculation that cybergangs are having a turf war by unleashing worms and malware all over the internet. The reason security experts are speculating that a bot war is going on is that some worms are undoing versions of other worms that were previously in place on infected computers.

These worms contain bot code that allows criminals to remotely control a computer. The infected computers are organized into networks, which are rented out to fraudsters. The bot networks are then used in phishing, pharming, and a host of other computer crimes designed to steal financial or personal information (identity theft).

The first worm (Zotob) appeared last Sunday then disappeared. After that several Zotob variants appeared and a another new worm (Bozori) appeared. In addition to this newer versions of already identifed worms began showing up (Rbot, Sdbot, Codbot and IRCbot).

Even CNN, ABC and the New York Times were compromised in this series of attacks, along with computers all over the world.

To protect yourself against this attack (Microsoft 2000 users are the most vulnerable) go to Microsoft's malware removal tool, which is free. Symantec Zotob Removal Tool is another free option to see if there is any damage to your system, along with options for repair/removal.

My theory is that awareness and communication, along with some old fashioned prosecution and political action are cures for the current outburst of financial and cyber crimes. If you want to help, always report any known attempts to law enforcement. Here is a good resource for doing this:

http://www.elsop.com/wrc/complain.htm

You might also pass on the removal tools to anyone you know that might have been compromised. Perhaps, we can take a bite out of this activity ourselves?

If you are interested in previous posts, I have done on gangs involved in financial and cyber crimes, here are links to them:

http://fraudwar.blogspot.com/2005/08/rumor-of-partnership-between-organized.html

http://fraudwar.blogspot.com/2005/07/mcafee-study-on-organized-crime-and.html

http://fraudwar.blogspot.com/2005/06/organized-fraud-gangs.html

http://fraudwar.blogspot.com/2005/06/fraud-gangs-plant-insiders.html

Saturday, August 20, 2005

Government Job Assistance Scams


Quite often on job sites and in classified advertising, there are ads stating they can get you U.S. Government jobs. For a fee these ads claim they can guarantee a position.

In most instances, people are directed to a toll free number, where someone tries to sell them study materials for a fee. These fraudulent services have also been known to lie about the availability of specific jobs in an area to reel in a customer (victim).

Many of these services will not give you any better chance of obtaining the job than if you applied for it yourself.

If you have been the victim of one of these scams call the Federal Trade Commission: 1-877-FTC-HELP (382-4357) or visit their website at www.ftc.gov and file a complaint. You can also complain to your state attorney general, or the Better Business Bureau.

Free information on government jobs can be found at www.usajobs.opm.gov. The bottom line is that information on civil service employment is in the public domain and no one should be charging for it.

Here is a link to an earlier post on identity theft occurring on job sites:

http://fraudwar.blogspot.com/2005/07/internet-resume-posting-and-fraud.html

To view the Federal Trade Commission's Alert on this activity, click here.

Friday, August 19, 2005

Opt Out From Becoming a Victim

For years, big businesses and specifically marketing gurus have been selling your personal information. Not only does this provide opportunities for criminals to steal your identity, but the offers (themselves) can be pretty darned annoying. There is now a service sponsored by the major credit bureaus in the United States, which gives you the opportunity to stop them from selling your information.

Just go to www.optoutprescreen.com and tell them to stop selling your information. You can also call 1-888-5-OPT-OUT.

It's a small step and won't stop all the junk mail from coming to your address, but it will help simplify your life and minimize your risk of becoming a victim of identity theft.

Another great resource in the era of Fraud, Phishing and Financial Misdeeds is the Federal Trade Commission's "Do Not Call List." They now accept cell phone numbers, also: http://www.ftc.gov/donotcall/