Writers of a password-stealing Trojan horse program have found that a little patience can lead to a lot of infections.
They have managed to infect hundreds of thousands of computers — including more than 14,000 within one unnamed global hotel chain — by waiting for system administrators to log onto infected PCs and then using a Microsoft administration tool to spread their malicious software throughout the network.
The criminals behind the Coreflood Trojan are using the software to steal banking and brokerage account user names and passwords. They’ve amassed a 50G-byte database of this information from the machines they’ve infected, according to Joe Stewart, director of malware research with security vendor SecureWorks.
Since Microsoft shipped its Windows XP Service Pack 2 software with its locked-down security features, hackers have had a hard time finding ways to spread malicious software throughout corporate networks. Widespread worm or virus outbreaks soon dropped off after the software’s August 2004 release.
But the Coreflood hackers have been successful, thanks in part to a Microsoft program called PsExec, which was written to help system administrators run legitimate software on computers across their networks.
For a widespread infection, attackers must first compromise a system on the network by tricking the user into downloading their program. Then, when a system administrator logs onto that desktop machine — to perform routine maintenance, for example — the malicious software tries to run PsExec and install malware on all other systems on the network.
Often the technique succeeds. Over the past 16 months, Coreflood’s authors have infected more than 378,000 computers. SecureWorks has counted thousands of infections in university networks and has found financial companies, hospitals, law firms, and even a U.S. state police agency that have had hundreds of infections.