Large Identity Theft Ring Uncovered
August 2005
The FBI is reportedly investigating a criminal operation that involves the theft of confidential data from thousands of machines infected with spyware.A security firm claims to have uncovered a huge identity-theft ring that appears to be using a spyware program to steal confidential information from computers.
Sunbelt Software said the operation, which is being investigated by the FBI and Secret Service, is gathering personal data from "thousands of machines" using keylogging software. The data collected includes credit card details, social security numbers, usernames, passwords, IM chat sessions and search terms. Some of the data gathered is then saved in a file hosted on a US-based server that has an offshore-registered domain, said Sunbelt president Alex Eckelberry.
"The types of data in this file are pretty sickening to watch," Eckelberry said in a blog posting from Saturday. "In a number of cases, we were so disturbed by what we saw that we contacted individuals who were in direct jeopardy of losing a considerable amount of money."
According to Sunbelt Software, criminals have obtained access to a considerable amount of bank information, including details about one company bank account containing over $350,000 (£197,000) and another account that has "readily accessible" funds of over $11,000.
The operation appears to be linked to CoolWebSearch (CWS), a malicious program that hijacks Web searches and disables security settings in the Internet Explorer browser. Patrick Jordan, a Sunbelt employee, discovered the identity theft ring while researching a CWS variant.
"During the course of infecting a machine, he [Jordan] discovered that a) the machine he was testing became a spam zombie and b) he noticed a call back to a remote server. He traced back the remote server and found an incredibly sophisticated criminal identity theft ring," said Eckelberry. "We are still trying to ascertain whether or not this is directly related to CWS."
Source...







