Virus Authors Use Amazon EC2 for Command & Control

Zbot (Zeus bot) is back again in another variation and is now taking advantage of Amazon EC2 for C&C.

Once a hapless attachment-clicker has opened the infected payload, such as the latest “xmas2.exe” or an infected website, code is injected into the victim’s system processes and then connects to the cloud to download it’s configuration (config.bin).

Read all the gory details here.

Leave a Reply

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>