Skip to main content

Massive Criminal Server Exposed

Massive Criminal Server Exposed

At the Black Hat conference last week, Joe Stewart of security firm SecureWorks reported on shutting down the main server for Coreflood, a criminal network that grew from a Trojan to become a massive repository of stolen data.

Coreflood was really noticed in 2004, when hackers infected a company with a Trojan and stole money from a US company. After that, however, it appeared to go underground. But earlier this year SecureWorks and Spamhaus shut down one of its servers and discovered 50 GB of stolen data – although SecureWorks says more than four times this amount had been previously harvested and discarded. The data included 3,233 credit card usernames and passwords, 8,485 bank and credit union usernames and passwords – all in all, a total of just under half a million usernames and passwords to over 35,000 domains.

How did they do it? By being slow and careful. After infecting one machine in a network they’d continue through the network until reaching a computer with administrative access, then use that to ensure infection of the entire network.

The good news is that the server was shut down. The bad news? The botnet it created remains active – everything has simply moved to Russia, and there may be more activity coming according to Stewart, who noted that one directory, created “a couple of weeks before we took the server offline, contained a Microsoft PowerPoint exploit, indicating the Coreflood group may have been interested in pursuing targeted attacks similar to those used by Chinese and Romanian hacking groups in recent months.”

Editors' Recommendations

Digital Trends Staff
Digital Trends has a simple mission: to help readers easily understand how tech affects the way they live. We are your…
Western Digital comes clean about massive security breach
western digital wd black d30 game drive 1 tb deal best buy march 2023

The popular PC storage manufacturer, Western Digital, has confirmed that it experienced a network security breach earlier this year, in which an unauthorized third party gained control of several of its systems.

The incident took place on March 26, 2023, but was immediately addressed by the manufacturer, with Western Digital reporting the breach bringing in top security experts to launch an investigation, which is currently ongoing, the company said in a statement.

Read more
‘Grim outlook’ as criminals commandeer AI chatbots, Europol says
ChatGPT and OpenAI logos.

Europol this week issued a stark warning highlighting the risks posed by criminals as they get to grips with the new wave of advanced AI chatbots.

In a post shared online this week, Europe’s law enforcement agency described how tools such as OpenAI's ChatGPT and GPT-4, and Google's Bard, will be increasingly used by criminals looking for new ways to con members of the public.

Read more
Nvidia built a massive dual GPU to power models like ChatGPT
Nvidia's H100 NVL being installed in a server.

Nvidia's semi-annual GPU Technology Conference (GTC) usually focuses on advancements in AI, but this year, Nvidia is responding to the massive rise of ChatGPT with a slate of new GPUs. Chief among them is the H100 NVL, which stitches two of Nvidia's H100 GPUs together to deploy Large Language Models (LLM) like ChatGPT.

The H100 isn't a new GPU. Nvidia announced it a year ago at GTC, sporting its Hopper architecture and promising to speed up AI inference in a variety of tasks. The new NVL model with its massive 94GB of memory is said to work best when deploying LLMs at scale, offering up to 12 times faster inference compared to last-gen's A100.

Read more