Twitter
BLN RSS
Add to Google




http://www.wikio.com



Share

News, Blogs,
Information, and Analysis

Rogue Government
What Really Happened
Deadline Live
Cryptogon
Vigilant Citizen
Raw Story
Citizens for Legit Gov.
Information Clearing House
American Free Press
Global Research
The Peoples Voice
Tom Burghardt
Uncover The News
All Gov.
Media Monarchy
Information Liberation
TPM Muckraker
F. William Engdahl
Cryptome
Narco News
Media Matters
Uruknet
Corbett Report
Common Dreams
Alternet
Antiwar
Aftermath News
Keith Johnson
Steve Quayle
Wayne Madsen
Truth Out
Etherzone
Online Journal
Lew Rockwell
Dissident Voice
Morph City
Sovereign Independent
Before It's News
News With Views
Jeff Rense
Strike The Root
Peter Chamberlin
Dprogram
12160
Old Thinker News
Activist Post
Common Dreams
Empire Burlesque
American Exile
CNS News
IntelliBreifs
Intel Trends
Electric Politics
Stop The Lie
Amy de Miceli
Crooks and Liars
Rumor Mill News
The Resident
Aangirfan
OpEDNews
The Brad Blog
Conspiracy Archive
Foreign Policy Journal
Counter Punch
August Review
Buzzflash
Truth Is Treason
Reason
Real News Network
VOA News
Huffington Post
World Net Daily
Drudge Report
Newsmax
Boing Boing
Short News
Small Government Times
Capitol Hill Blue
Global Post
NewsWires
Yahoo!-Top Headlines
Yahoo!-Full Coverage
AP-National News
UPI
Reuters
WorldNews.com
7am.com
1st Headlines
My Way - News
Ananova.com
Lycos News - Breaking
CNews - Top News
Sky News
Guardian Unlimited
Newswire - Salon.com
NewsNow.co.uk
news-spider.com
Community News Aggregators
Reddit
Digg
Business / Economics
Seeking Alpha
Market Watch
Bloomberg
Wall Street Journal
RTT News
CNN Money
Forbes
Business Week
Funny Money Report
Market Oracle
Money Morning
The Street
Shadow Stats
Economist
Financial Times
Fortune Magazine
Kitco
Gold Eagle
Max Keiser
321 Gold
Stock Charts
Zero Hedge
Washingtons's Blog
The Daily Reckoning
Energy Business Review
Milplex / Intel / Defense
Danger Room
Washington Technology
Defense Industry Daily
Global Security
Geopolitical Monitor
Defense Link
Stratfor
Space War
Jane's
Defense Tech
Strategy Page
Military Info Tech
Health & Environment
Natural News
Health Wyze
Major US Newspapers
New York Times
New York Post
New York Daily News
Washington Post
Washington Times
L.A. Times
USA Today
Science / Tech News
Techno Fascism Blog
Wired
Blast Magazine
PHYSorg
Science Daily
Popular Science
Engadget
New Scientist
DVice
Technovelgy
Singularity Hub
H+ Magazine
Science Magazine
Seed Magazine
CBR Online
Science News
SlashDot
Scientific American
Spectrum IEEE
Technology Review
io9
ZD Net
Technology News
The Register
Tech News World
VNU Net
Satire & Animation
The Blotch
Reptile God
Wahoos Mopar Grave Yard
Royal Canadian Air Farce
The Daily Show
The Colbert Report
Mark Fiore
All Hat No Cattle
Mack White
Propaganda Remix Project
Internet Weekly Report
Kontraband
Holy Lemon






Directive 21

Emergency Seed Vault





AddThis Feed Button
FKN NEWZ Add to Technorati Favorites
Valid XHTML 1.0 Transitional







More than 75,000 computer systems hacked in one of largest cyber attacks, security firm says
Published on 02-18-2010Email To Friend    Print Version
Share |

Source: Washington Post

More than 75,000 computer systems at nearly 2,500 companies in the United States and around the world have been hacked in what appears to be one of the largest and most sophisticated attacks by cyber criminals discovered to date, according to a northern Virginia security firm.

The attack, which began in late 2008 and was discovered last month, targeted proprietary corporate data, e-mails, credit-card transaction data and login credentials at companies in the health and technology industries in 196 countries, according to Herndon-based NetWitness.

News of the attack follows reports last month that the computer networks at Google and more than 30 other large financial, energy, defense, technology and media firms had been compromised. Google said the attack on its system originated in China.

This latest attack does not appear to be linked to the Google intrusion, said Amit Yoran, NetWitness's chief executive. But it is significant, he said, in its scale and in its apparent demonstration that the criminal groups' sophistication in cyberattacks is approaching that of nation states such as China and Russia.

The attack also highlights the inability of the private sector -- including industries that would be expected to employ the most sophisticated cyber defenses -- to protect itself.

"The traditional security approaches of intrusion-detection systems and anti-virus software are by definition inadequate for these types of sophisticated threats," Yoran said. "The things that we -- industry -- have been doing for the past 20 years are ineffective with attacks like this. That's the story."

The intrusion, first reported on the Wall Street Journal's Web site, was detected Jan. 26 by NetWitness engineer Alex Cox. He discovered the intrusion, dubbed the Kneber bot, being run by a ring based in Eastern Europe operating through at least 20 command and control servers worldwide.

The hackers lured unsuspecting employees at targeted firms to download infected software from sites controlled by the hackers, or baited them into opening e-mails containing the infected attachments, Yoran said. The malicious software, or "bots," enabled the attackers to commandeer users' computers, scrape them for log-in credentials and passwords -- including to online banking and social networking sites -- and then exploit that data to hack into the systems of other users, Yoran said. The number of penetrated systems grew exponentially, he said.

"Because they're using multiple bots and very sophisticated command and control methods, once they're in the system, even if you whack the command and control servers, it's difficult to rid them of the ability to control the users' computers," Yoran said.

The malware had the ability to target any information the attackers wanted, including file-sharing sites for sensitive corporate documents, according to NetWitness.

Login credentials have monetary value in the criminal underground, experts said. A damage assessment for the firms is underway, Yoran said. NetWitness has been working with firms to help them mitigate the damage.

Among the companies hit were Cardinal Health, located in Dublin, Ohio, and Merck, according to the Wall Street Journal. A spokesman for Cardinal said the firm removed the infected computers as soon as the breach was found.

Also affected were educational institutions, energy firms, financial companies and Internet service providers. Ten government agencies were penetrated, none in the national security area, NetWitness said.

The systems penetrated were mostly in the United States, Saudi Arabia, Egypt, Turkey and Mexico, the firm said.