Mobile Version
Subscribe
Contact Us
About Us
Advertising
Editorial
SC UK
SC Aus/NZ
Home
News
Features
Opinions
News Bytes
Editorial Videos
In Focus Videos
Products
Podcasts
Canada
Newsletters
Products
Group Tests
First Looks
Products
About Reviews
Blogs
The News Team Blog
The Data Breach Blog
The SC Magazine Awards Blog
Extras
ebooks
Case Studies
Slideshows
Spotlights
Buyers Guide
Whitepapers
IT Security Jobs
Events
SC Awards U.S.
SC Congress Canada
SCWC 24/7
SC Awards Canada
SC Congress New York
Editorial Webcasts
Vendor Webcasts
Subscribe
Newsletters
Subscribe to SC
Archive
Archive
Featured Topics:
Patches
Malware
Breaches
Government
Cybercrime Corner
Congress Canada
Canada News
RSS
|
Login
|
Register
SC Magazine
>
News
> "Byzantine" botnet uses military, education servers for spam
"Byzantine" botnet uses military, education servers for spam
Jim Carr
May 02, 2008
Print
Email
Reprint
Permissions
Text:
A
|
A
|
A
Related Articles
Gasoline spam hits inboxes
Romania phishing ring busted
Cyberattack repairs cost Pentagon $100 million in six months
Hackers hit U.S. Army websites
More News
Trojan appears that leverages patched Microsoft Office flaw
New Chrome version contains malware download security
Microsoft issues patch plans, includes Internet Explorer fix
Standards body to certify PCI end-user experts
Breaches aided by weak passwords, poor AV detection
RELATED TOPICS
Email Security
Government
Emerging Threats
Lawbreakers & Cybercrime
Trojans
More in News:
Forensic exam concludes no breach happened at university
Read More >>
Researchers at an Eastern European security company have uncovered a spam-sending scheme of "Byzantine complexity" that attempts to use military and university email servers to send junk email.
The discovery by Romania-based BitDefender came after the company identified spam e-mails that claimed to contain links to videos. When users click the link to view the video, however, they were prompted to download a media player, which actually was Backdoor.Edunet.A, a trojan that uses victims' compromised computers as a channel for sending commands to a series of mail servers.
The Edunet backdoor creates a botnet used to attempt to send spam via a list of mail servers, BitDefender said in an online posting available
here
. The mail servers are mostly in the .edu and .mil domains.
"It's not every day that you stumble on the workings of an honest-to-God hacking ring, let alone one that has a predilection for using military- and university-run mail servers as spam relays," Sorin Dudea, BitDefender's head of antivirus research, wrote in the online posting. "It would be interesting to identify what, if anything, the institutions that own the targeted servers have in common."
The trojan sends the commands hoping to find an open relay -- a mail server misconfiguration that spammers often use to camouflage the origins of their spam. This techniques essentially makes it appear that any email originating from the trojan is in fact one sent from the open relay, according to BitDefender.
The list of servers is retrieved by the trojan from a series of web servers that are compromised themselves or part of the attackers' own network, according to BitDefender. The list of web servers is continuously changing, but that of the targets has, so far, remained constant, the company said.
BitDefender researchers said that none of the servers in the current target list is actually vulnerable.
Please enable JavaScript to view the
comments powered by Disqus.
Sponsored Links
Most Popular
Most Emailed
Most Recent
FBI call gives clues into Anonymous, LulzSec probes
Anonymous raids law firm over its defense of Marine
Deadline looms to remove click-fraud malware
MasterCard announces product future around EMV
Risk: Security's new compliance
Don't let Wi-Fi hotspots get the best of you
Symantec code posted despite attempt to trap suspect
Standards body to certify PCI end-user experts
Phishing email leads to Denver area health care breach
Microsoft issues patch plans, includes Internet Explorer fix
Risk: Security's new compliance
Deadline looms to remove click-fraud malware
FBI call gives clues into Anonymous, LulzSec probes
Anonymous raids law firm over its defense of Marine
Standards body to certify PCI end-user experts
Breaches aided by weak passwords, poor AV detection
MasterCard announces product future around EMV
Phishing email leads to Denver area health care breach
Don't let Wi-Fi hotspots get the best of you
Security vendors can no longer ignore patch management
Trojan appears that leverages patched Microsoft Office flaw
Microsoft issues patch plans, includes Internet Explorer fix
Standards body to certify PCI end-user experts
Breaches aided by weak passwords, poor AV detection
Hacktivist-led DDoS is now the most common type, study finds
Anonymous renders Canadian Nazis not-so-anonymous
Cavoukian slams Supreme Court
SDA, McAfee mark Canada's card
Symantec code posted despite attempt to trap suspect
MasterCard announces product future around EMV
Powered by Disqus
Popular Topics
Analyst Reports & Industry Surveys
Android
Anonymous
Breaches & Exposures
Canada
Data Breaches
DNS
Education
Finance
Government
Hackers
Hacktivism
Health Care
Lawbreakers & Cybercrime
Lawsuit
Legislation
LulzSec
Malware
Mobile Applications
Mobile Devices
Patch Management
PCI Compliance
SC Awards 2012
Trojans
Vulnerabilities & Flaws