{"id":1809,"date":"2010-01-19T16:09:57","date_gmt":"2010-01-19T21:09:57","guid":{"rendered":"http:\/\/rbachnet.wwwmi3-ss40.a2hosted.com\/?p=1809"},"modified":"2021-08-08T18:22:35","modified_gmt":"2021-08-08T22:22:35","slug":"zeus-raids-school","status":"publish","type":"post","link":"https:\/\/rbach.net\/index.php\/zeus-raids-school\/","title":{"rendered":"Zeus Raids School"},"content":{"rendered":"<p><a href=\"http:\/\/people.duke.edu\/~tkb13\/courses\/ncsu-csc405-2015fa\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-110910 size-medium\" title=\"Zeus Raids School\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_theft2-7.jpg?resize=150%2C122&#038;ssl=1\" alt=\"Zeus Raids School\" width=\"150\" height=\"122\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_theft2-7.jpg?resize=150%2C122&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_theft2-7.jpg?resize=75%2C61&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_theft2-7.jpg?w=550&amp;ssl=1 550w\" sizes=\"auto, (max-width: 150px) 100vw, 150px\" \/><\/a>A New York <strong>school district<\/strong> was a victim of an apparent <strong>Zeus trojan attack<\/strong> which appears to have netted nearly <strong>$500,000<\/strong>. <a href=\"https:\/\/www.informationweek.com\/\" target=\"_blank\" rel=\"noopener noreferrer\"><em>InformationWeek<\/em><\/a> is reporting that the <a href=\"https:\/\/www.fbi.gov\" target=\"_blank\" rel=\"noopener noreferrer\">FBI<\/a> and <a href=\"https:\/\/troopers.ny.gov\/computer-crimes\" target=\"_blank\" rel=\"noopener noreferrer\">New York State Police Cyber Crime and Critical Infrastructure Unit<\/a> are investigating an attempt last month to steal about <strong>$3.8 million<\/strong> from the <a href=\"https:\/\/www.duanesburg.org\/\" target=\"_blank\" rel=\"noopener noreferrer\">Duanesburg Central School District<\/a> near <span class=\"search-header-subheader\"><span class=\"search-header-title__location\"><a href=\"https:\/\/www.cityofschenectady.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Schenectady, New York<\/a>.<\/span><\/span><\/p>\n<p>According to the January 6 article, online thieves made a series of <strong>unauthorized funds transfers<\/strong> from the school district&#8217;s <a href=\"https:\/\/www.nbtbank.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">NBT Bank<\/a> account to an <strong>overseas bank<\/strong> between December 18 and 22, 2009. The third transfer during this period was flagged as abnormal activity by the bank, which began blocking pending transactions after the school district confirmed the transfers had not been authorized. Working with foreign banks, NBT Bank <strong>recovered about $2.5 million out of $3 million stolen<\/strong> during the four-day period, but two previous unauthorized transactions were discovered.<\/p>\n<p>&#8220;<em>Thanks to NBT Bank&#8217;s aggressive pursuit of the stolen funds, we are fortunate that the vast majority of the money has been recovered,<\/em>&#8221; wrote Superintendent Christine Crowley in a letter on Monday to district parents and community members. &#8220;<em>However, $497,200 of Duanesburg taxpayers&#8217; money is still missing, and we are committed to doing everything in our power to recover the remaining funds.<\/em>&#8221;<\/p>\n<p>The district <a href=\"https:\/\/www.facebook.com\/duanesburgschools\" target=\"_blank\" rel=\"noopener noreferrer\">website<\/a> says, &#8220;<em>At this time, we do not have any more information on how this happened and do not expect to have any more information to share until the investigation concludes.<\/em>&#8221;<\/p>\n<p>Security researchers at <a href=\"https:\/\/www.trusteer.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Trusteer<\/a> point out in a recent <a href=\"https:\/\/www.darkreading.com\/\" target=\"_blank\" rel=\"noopener noreferrer\"><em>DarkReading<\/em><\/a> <a href=\"https:\/\/web.archive.org\/web\/20100920084653\/http:\/\/www.darkreading.com:80\/security\/antivirus\/showArticle.jhtml?articleID=220000718\" target=\"_blank\" rel=\"noopener noreferrer\">article<\/a> that <strong>Zeus is detected only 23 percent of the time<\/strong> by up-to-date anti-virus applications. The massive <a title=\"Zeus (trojan horse)\" href=\"http:\/\/en.wikipedia.org\/wiki\/Zeus_%28trojan_horse%29\" target=\"_blank\" rel=\"noopener wikipedia noreferrer\"><strong>Zbot<\/strong><\/a><strong> botnet<\/strong> is made up of <strong>3.6 million PCs in the U.S.<\/strong>, according to <a href=\"https:\/\/www.securityweek.com\/damballa-vanishes-fire-sale-core-security\" target=\"_blank\" rel=\"noopener noreferrer\">Damballa<\/a> data\u00a0 The malware <strong>steals users&#8217; online financial credentials<\/strong> and moves them to a remote server, where it can <strong>inject HTML<\/strong> onto pages rendered by the victim&#8217;s browser to display its own content mimicking, for instance, a bank&#8217;s Web page.<\/p>\n<p>&#8220;<em>Zeus&#8217; infection rate is higher than that of any other financial Trojan. We are seeing actual fraud linked to Zeus &#8212; accounts being compromised, [and] money transferred from accounts of customers infected with Zeus,<\/em>&#8221; <a title=\"Mickey Boodaei\" href=\"https:\/\/www.linkedin.com\/in\/mickeyboodaei\/\" target=\"_blank\" rel=\"crunchbase noopener noreferrer\">Mickey Boodaei<\/a>, founder and CEO of Trusteer told <em>DarkReading<\/em>. &#8220;<em>When we investigate some of our banking customers&#8217; [machines infected by it], we find evidence of abuse on the computer, so we know this crime ring is very active and dangerous.<\/em>&#8221;<\/p>\n<p>The security blog says that organizations can\u2019t control the <strong>transmission vectors<\/strong>, which are increasingly <strong>social networking<\/strong> and\/or webmail applications. Given the high degree of user trust and huge user populations, malware developers have been <strong>targeting social networks aggressivel<\/strong>y (webmail is a well-established transmission vector). Some of the threats come in the form of <strong>social network-specific threats<\/strong> (e.g., koobface, fbaction), but many times they\u2019re re-using existing or older threats delivered in a new, hybrid way \u2013 <strong>exploiting the trust associated with social networks<\/strong> \u2013 which has given threats like Zeus a huge boost. If you can\u2019t control the transmission vector, it\u2019s much harder to manage the threat\u2026especially when <strong>users click first, and think later<\/strong>.<\/p>\n<h6>Related articles<\/h6>\n<ul>\n<li><a href=\"https:\/\/web.archive.org\/web\/20131115034026\/http:\/\/www.techweekeurope.co.uk\/news\/court-order-allows-microsoft-to-retain-control-of-zeus-botnets-100741\" target=\"_blank\" rel=\"noopener noreferrer\">Court Order Allows Microsoft To Retain Control Of Zeus Botnets<\/a> (techweekeurope.co.uk)<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><em><a title=\"Ralph Bach\" href=\"https:\/\/rbach.net\/index.php\/new-resume\/\" target=\"_blank\" rel=\"noopener noreferrer\">Ralph Bach<\/a>\u00a0has been in IT long enough to know better and has blogged from his\u00a0<a title=\"Bach Seat\" href=\"https:\/\/rbach.net\/\" target=\"_blank\" rel=\"noopener noreferrer\">Bach Seat<\/a> about IT, careers, and anything else that catches his attention since 2005. You can follow him on <a class=\"broken_link\" href=\"http:\/\/www.linkedin.com\/in\/rb48334\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">LinkedIn<\/a>,\u00a0<a href=\"https:\/\/www.facebook.com\/ralph.bach.14\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook<\/a>,\u00a0and\u00a0<a href=\"https:\/\/twitter.com\/rbach48334\" target=\"_blank\" rel=\"noopener noreferrer\">Twitter<\/a>. Email the Bach Seat\u00a0<a href=\"mailto:\/\/bach.seat@gmail.com\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>NY school district was a victim of Zeus trojan attack that netted nearly $500,000.as part of an attempt to steal $3.8 million from the Duanesburg Schools<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[3240,58,128,4,1071,1468,3022,127],"class_list":["post-1809","post","type-post","status-publish","format-standard","hentry","category-security","tag-3240","tag-botnet","tag-k12","tag-security","tag-theft","tag-trusteer","tag-zbot","tag-zeus"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/1809","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/comments?post=1809"}],"version-history":[{"count":14,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/1809\/revisions"}],"predecessor-version":[{"id":132113,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/1809\/revisions\/132113"}],"wp:attachment":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/media?parent=1809"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/categories?post=1809"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/tags?post=1809"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}