Categorized | Security

Introducing: SpyEye Tracker

It’s now more than one and a half year ago, when I’ve published ZeuS Tracker.

During the last few weeks SpyEye (a Crimeware kit like ZeuS) has obtained a lot of media attention. In October 2010 it came out that ZeuS merges with SpyEye. There has been a lot of speculations on this topic and it looks like that after the recent ZeuS arrests (see link one / link two) it got to hot for the author of the ZeuS Crimeware so he decided to stop developing and selling the ZeuS Crimeware Kit. Additionally the ZeuS Author has passed the source code of the ZeuS Trojan over to the SpyEye author.

So what does that mean for the Security Community? Personally I think there are two scenarios:

  1. SpyEye will become the new super banking trojan
  2. Even if ZeuS is dead it will stay as a rival of SpyEye and the cybercriminals won’t stop using it as long as ZeuS works well

From what I’ve seen and heard during the past days I think most likely ZeuS will stay at the top of the most used Crimeware kits aswell as stay as a rival of SpyEye. But that doesn’t matter anyway: To stay on the secure side I’ve decided to do some effort that SpyEye will not get the next ‘ZeuS’ Trojan. My goal is to put SpyEye into the spotlight before it becomes a ‘big’ threat like ZeuS was in the past (in the bloom time ZeuS Tracker has tracked over 200 active ZeuS C&Cs). To reach this goal I’ve developed another tracking system for ISPs, CERTs and law enforcement. Introducing: SpyEye Tracker.

*** Some words about SpyEye Tracker ***

There isn’t a really big difference between SpyEye Tracker and ZeuS Tracker. As a side note please let me mention that not all features which are available on ZeuS Tracker are yet implemented on SpyEye Tracker at this time. I will try to fix the missing features during the next few weeks.

What is new on SpyEye Tracker is the news section where I’ve planned to publish a new post whenever I make a change to the SpyEye Tracker.

If you have any question please don’t hesitate to drop me a line using the contact form.

Enjoy :)

You can also follow abuse.ch on Twitter: twitter.com/abuse_ch

*** Further links ***

Bookmark, tagg it or email it to a friend:

View full post on abuse.ch

Related Posts
  • Introducing: Palevo Tracker
    Today we are going to talk about a nasty worm called Palevo. Palevo (also known as Rimecud, Butterfly bot or Pilleuz) made some big press in 2009 when Panda Security announced the coordinated takedown...
  • New Mitmo: SpyEye Edition
    Our Threat Research team just completed some interesting analysis of a new Man-in-the-mobile (Mitmo) Symbian trojan (designed to steal mTANs), and what's particularly interesting about this va...
  • Facebook Stalker Tracker Tool Turns Users into Spammers
    Privacy has been one of the major concerns of Facebook users roday, especially as the social network continues to increasingly grow to become a massive directory of personal information. Users are bec...
  • Zeus and SpyEye: Old Dogs Repeat Old Tricks
    There is a lot of buzz in the security community lately about the merger of two widespread password-stealing malware families, Zbot (maker of Zeus) and SpyEye. Some reports says that the Zbot source ...
  • SpyEye, the infostealing trojan leader
    Everyone is talking about the SpyEye Trojan, the info stealer malware that gained all the attention after the author of ZeuS left the underground market and sold ZeuS sources to the SpyEye team. We a...
  • ZeuS Tracker goes Arbor
    I’m very excited today to announce that Arbor Networks, one of the leading vendors providing DDoS Protection and Network Security world-wide, has added a fingerprint in their Peakflow product fa...
  • ZeuS Tracker Online Again With New Features
    As most of you probably noticed, ZeuS Tracker was offline for a whole week (2010-09-03 to 2010-09-14). During this time I made several improvements and added new features to ZeuS Tracker. But before ...
  • Creeper Tracker Pro creeps around on Facebook
    Sunbelt Blog -- Is it time to examine another Facebook scam? Why yes, it is. Located at…deep breath…99percentofgirlswouldkilltheirboyfriends(dot)info, this website takes the form of the familiar...
  • SpyEye from Moldova
    Here is a site that looks serious and legitimate: ecurrencynews.org It has some good stories, and some not so good… Following certain links will lead to a ‘Java Update’ page. ItR...
  • The SpyEye Interface Part 2: SYN 1
    This is part 2 of a two-part blog covering the SpyEye interface. In the first part, we looked into CN 1 aka the Main Access Panel and how it is used. In this part, we are going to talk about SYN 1 or ...

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
5 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
5 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
5 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
5 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
5 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
5 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
5 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
5 months ago
Some free-based music we play at work http://t.co/xu5agZfc
5 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
5 months ago