Skip the navigation

Credit report breach has link to Zeus banking malware

The website used to release the information can be traced to a Zeus-related email address

By Jeremy Kirk
March 18, 2013 11:13 PM ET

IDG News Service - A website that leaked credit reports of celebrities and government officials last week appears to have a curious link to the malicious banking software known as "Zeus."

Scot A. Terban, an independent information security analyst known by his blogging pseudonym Krypt3ia, used a software tool called Maltego to research "Exposed.su," which caused a stir last week by posting personal information and credit reports for FBI Director Robert Mueller and singer Beyonce, among others. The FBI and U.S. Secret Service are investigating.

Exposed.su is no longer online. But by using Maltego, an advanced tool for tracking down digital information scattered about the Internet, Terban put together an interesting snapshot of who may be behind it.

The domain registration for Exposed.su listed an email address "exposed.su@allperson.su." Terban researched the "allperson.su" domain, looking at email addresses and other domains affiliated with the address.

He found "a pattern of behavior showing that most of these email addresses were for scam sites, free MP3 or video sites," according to a writeup on his blog.

One of the most interesting finds is a related email address: demand.su@allperson.ru. That email address is listed in a civil suit filed by Microsoft in U.S. District Court for the Eastern District of New York in March 2012.

The lawsuit lists as plaintiffs 39 unnamed defendants who are accused of running the Zeus botnet, a long-running scheme believed to have stolen up to $100 million from online bank accounts over at least five years. Microsoft later named two defendants already in prison in the U.K.

The particular email address was affiliated with a domain, now offline, that was one of thousands Microsoft alleged were used as part of the Zeus botnet.

Information in whois, a global address book of website owners, showed that allperson.su was registered by "Andrej V. Punegov" in 2007. Information in the whois, however, is notoriously inaccurate and contains false information.

Nonetheless, Terban's work shows that a bit of research can show surprising information. Cybercriminals are known at times to make mistakes in covering their digital tracks.

Terban said in an interview on Monday that the data breach appeared to have the tone of a bunch of teenage hackers. "It seems like somebody just tried to show off, maybe with a bit of an axe to grind against certain people," Terban said.

Even after the data breach had generated significant media coverage, the website continued to add data on more celebrities. But Terban noted the links to government officials became inoperable, even though the links to celebrity data still worked, indicating some sort of intervention was occurring before it fell offline.

Reprinted with permission from IDG.net. Story copyright 2014 International Data Group. All rights reserved.
Our Commenting Policies