{"id":349360,"date":"2017-08-30T14:36:03","date_gmt":"2017-08-30T14:36:03","guid":{"rendered":"http:\/\/citifmonline.com\/?p=349360"},"modified":"2017-11-10T12:36:00","modified_gmt":"2017-11-10T12:36:00","slug":"giant-spambot-scooped-up-711-million-email-addresses","status":"publish","type":"post","link":"https:\/\/citifmonline.com\/?p=349360","title":{"rendered":"Giant spambot scooped up 711 million email addresses"},"content":{"rendered":"<p>A malware researcher has discovered a spamming operation that has been drawing on a list of 711.5 million email addresses.<\/p>\n<p>The scale of the scheme appears to make it the biggest find of its kind.<\/p>\n<p>The addresses &#8211; and in some cases associated passwords &#8211; have apparently been gathered to help spread banking malware.<\/p>\n<p>Members of the public can check if their accounts have been affected via the Have I Been Pwned service.<br \/>\nIts operator, Troy Hunt, acknowledged that some of the listed addresses corresponded to non-existent accounts.<br \/>\nBut he added that the number that had been collated still totalled a &#8220;mind-boggling amount&#8221;.<\/p>\n<p><strong>Hidden images<\/strong><br \/>\nThe Spambot discovery was first flagged by a Paris-based security expert who calls himself Benkow.<br \/>\nIt was then brought to wider attention by the ZDnet news site.<\/p>\n<p>The database of 711 million user details can be divided in two.<\/p>\n<p>In cases where the attackers know only an email address, they can only target the owner with spam in the hope of tricking them into revealing more information.<\/p>\n<p>But in cases where they also have the user&#8217;s login password and other details, they can secretly hijack their accounts to aid their campaign via a spambot known as Onliner.<\/p>\n<p>Benkow acknowledged that it was &#8220;difficult to know where [the] credentials had come from&#8221;, but suggested that they might have been gathered from previous leaks, a Facebook phishing campaign and illegal sales of hacking victims&#8217; details.<\/p>\n<p>In some cases, the perpetrators had gathered details of the accounts&#8217; simple mail transfer protocol (SMTP) server and port settings.<\/p>\n<p>This information could be used to fool email providers&#8217; spam-detecting systems into letting messages through that might otherwise have been blocked.<\/p>\n<p>&#8220;While the list of mailable addresses is quite large, it is probably no larger than any seen previously,&#8221; Richard Cox, former chief information officer of the Spamhaus project, told the BBC.<\/p>\n<p>&#8220;The lists of compromised accounts are more worrying.<\/p>\n<p>&#8220;When compromised accounts are used for spam, they can only be stopped by their providers suspending the account &#8211; but when that many are involved, it will severely overload the security\/abuse departments of those providers, making it a slow process and that is what keeps the spam flowing.&#8221;<\/p>\n<p>Benkow added that the Onliner spambot had been hiding tiny pixel-sized images in the emails it had sent out, which were used to harvest information about recipients&#8217; computers.<\/p>\n<p>This meant that the right kinds of malware attachments required to infect different types of devices could be included when follow-up messages masquerading as business invoices were delivered.<\/p>\n<p>Mr Hunt said that the Spambot lists had been tracked to a Netherlands-based computer server, but it had yet to be shut down.<\/p>\n<p>For now, affected users are able to check only if their email addresses have been targeted, but not if their accounts have been hijacked.<\/p>\n<p>But Benkow told the BBC there were still protective steps affected users could take.<\/p>\n<p>&#8220;I recommend you to change your password, and be more vigilant with the emails that you receive, now you know that you&#8217;re on malware deliverers&#8217; lists,&#8221; he said.<\/p>\n<p>&#8211;<\/p>\n<p>Source: BBC<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A malware researcher has discovered a spamming operation that has been drawing on a list of 711.5 million email addresses. The scale of the scheme appears to make it the biggest find of its kind. The addresses &#8211; and in some cases associated passwords &#8211; have apparently been gathered to help spread banking malware. Members [&hellip;]<\/p>\n","protected":false},"author":14,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jnews-multi-image_gallery":[],"jnews_single_post":[],"jnews_primary_category":[],"jnews_social_meta":[],"jnews_override_counter":[],"footnotes":""},"categories":[106],"tags":[10694,7083,10695],"class_list":["post-349360","post","type-post","status-publish","format-standard","hentry","category-technology","tag-711-million-email-addresses","tag-malware","tag-spambot"],"_links":{"self":[{"href":"https:\/\/citifmonline.com\/index.php?rest_route=\/wp\/v2\/posts\/349360","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/citifmonline.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/citifmonline.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/citifmonline.com\/index.php?rest_route=\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/citifmonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=349360"}],"version-history":[{"count":0,"href":"https:\/\/citifmonline.com\/index.php?rest_route=\/wp\/v2\/posts\/349360\/revisions"}],"wp:attachment":[{"href":"https:\/\/citifmonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=349360"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/citifmonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=349360"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/citifmonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=349360"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}