Infamous Russian malware gang disappears

An alleged Russian malware hosting gang has abruptly disappeared, according to Trend Micro.

The Russian Business Network (RBN), which was allegedly heavily involved in hosting malware packing kits -- development suites for malware -- suddenly dropped off the Internet on Tuesday, said the security company.

"It feels like their upstream providers put them on a black list, and terminated services to this problematic customer," said Raimund Genes, chief technology officer for Trend Micro's antivirus division, on Friday.

Researchers from Internet security company VeriSign said that RBN has been able to offer "bullet-proof hosting" for malware by means of links to the Russian government.

Genes claimed it is likely that whatever protection RBN enjoyed was withdrawn because the group had overreached itself. "All kinds of cybercrime was on RBN sites, but recently they've become too greedy," said Genes. "They infiltrated a Turkish government site so that it pointed to a site in Panama that was registered under RBN. [The site] was rented to multiple malware gangs."

Genes added that some US government and Brazilian sites, which he declined to identify specifically, had been compromised through SQL injection attacks to make them point to other RBN sites compromised with malware. "Maybe some government was upset by [RBN] activity," said Genes.

Although Trend Micro says it cannot be 100 percent sure, the company believes that the gang has shifted operations to Asia. Sites hosted in Taiwan and China are now hosting malware packing kits and malware which had been commonly hosted on RBN sites.

"Sites in Taiwan and China are now hosting malware with the same behaviour," said Genes. "MPack [packer kit] and its IcePack add-on are being offered, as well as Iframe exploits."

MPack is a PHP-based malware kit that allows its developers to sell modules of malicious code, while Iframe malware targets browsers by attacking vulnerabilities in the way they handle Iframe HTML tags.

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal IT: Govt's cost-cutting bitch
    The government needs to stop looking at IT as a necessary evil or the place to remove costs when the Treasurer comes calling.
  • Array Can complaints on mobile content be cut?
    On 1 July this year the new Mobile Premium Services Code was introduced. It sounds like it's had a good impact, but is it enough?
  • Array NZ farmers: Bleating about broadband
    As we know, farmers are such bleaters. They bleat as much as the four-legged woolly things in their paddocks. If it's not the weather, it's the strength of the dollar! Nothing is ever right. Likewise with rural broadband.
  • More blogs »

Tags

Back to top

Featured