New Trojan stealing FTP credentials, attacking FTP websites --- (2009-06-30)

Security researchers have discovered a new Trojan that has harvested as many as 80,000 unique FTP server logins and is now beginning to target domains, injecting malicious scripts into compromised FTP sites.

Security researchers have discovered a new Trojan that has harvested as many as 80,000 unique FTP server logins and is now beginning to target domains, injecting malicious scripts into compromised FTP sites.

"The list is now so large we have no way to effectively inform companies in a meaningful timeframe," Jacques Erasmus, director of research at Prevx. "I suspect we'll see an increase in drive by malware in the next day or two."

In five minutes one infected client managed to inject malicious JavaScript into 85 FTP websites. Once malicious script is injected into a page, it automatically scans the software running on visitor's machines looking for a way in. If a flaw is found, the script deploys a specially crafted package of malware onto the machine that steals passwords and other sensitive information. The Trojan, a variant of the Zeus family, also scours the machine's stored form cache looking for stored FTP login credentials.

Read the full article from SearchSecurity.com