'Pony' botnet stealing Bitcoin and other virtual currencies: Trustwave

Advertisement
By Reuters | Updated: 25 February 2014 16:19 IST
Cybercriminals have infected hundreds of thousands of computers with a virus called "Pony" to steal Bitcoins and other digital currencies, in the most ambitious cyber-attack on virtual money uncovered so far, according to security firm Trustwave.

Trustwave said on Monday that it has found evidence that the operators of a cybercrime ring known as the Pony botnet have stolen some 85 virtual "wallets" that contained Bitcoins and other types of digital currencies. The firm said it did not know how much digital currency was contained in the wallets.

"It is the first time we saw such a widespread presence of this type of malware. It was on hundreds of thousands of machines," said Ziv Mador, security research director with Chicago-based Trustwave.

Trustwave said it believes the crime ring is still operating, though it does not know who is running the group. The company said it has disrupted the servers that were controlling machines infected with Pony, but expects the group to launch more attacks on virtual currency users.

Advertisement

A representative for the Bitcoin Foundation, a trade group that promotes adoption of the virtual currency, advised Bitcoin users to store their currency offline in a secure location to prevent cyber criminals from stealing them.

Advertisement

"Electronic wallet security continues to improve by leaps and bounds as hardware wallets become available and we start to see software wallets that support multi-signature transactions," said the Bitcoin Foundation's director of public affairs, Jinyoung Lee Englund.

Trustwave's discovery comes after an unrelated cyber attack that spammed Bitcoin exchanges earlier this month. That attack prompted at least three online virtual currency traders to halt withdrawals, causing Bitcoin's value to plunge 33 percent over three weeks.

Advertisement

Bitcoin is a digital currency sustained by software code written by an unknown programmer or group of programmers. It is not governed by any one company or person, and its value is determined by user demand.

People who buy digital currency can store it in virtual wallets on their own machines or with companies that offer storage and security services.

Advertisement

Mador said digital currency theft is still in its infancy, but that it is likely to grow. He said that digital currency buyers can protect themselves from hackers by using encrypted files.

"Most websites don't encrypt them by default, but you can turn them on," he added.

New opportunity
Botnets are collections of infected computers that take orders from central "command and control" servers. The botnets steal data from compromised PCs and can also deliver other types of malware that force them to perform tasks.

This is at least the third type of fraud to surface involving digital currencies. Criminals have previously hacked into marketplaces where digital currencies are traded by exploiting security flaws in those sites, then stealing those currencies, according to Trustwave.

Cyber criminals have also developed botnets that force enslaved computers to create, or "mine", digital currencies, which the fraudsters then claim as their own.

Bitcoin mining is a time-consuming process in which computers perform complex math calculations. The operators of those botnets are stealing electricity and data center resources when they use compromised machines to mine digital currencies.

Trustwave in December uncovered a trove of some 2 million stolen passwords to websites including Facebook Inc, Google Inc, Twitter Inc and Yahoo Inc while probing a command and control server using a less sophisticated version of the Pony malware.

Trustwave said on Monday that the new version of Pony compromised another 600,000 website credentials.

© Thomson Reuters 2014

 

Also seeCryptocurrency Prices across Indian exchanges

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Amazon Great Indian Festival Sale: Deals on Smartphones, Laptops Teased
  2. Vivo Launches Y500 in China With a Massive 8,200mAh Battery
  3. Lenovo Legion Go 2's Price Has Been Tipped Ahead of Reveal
  4. Xiaomi 15T Arrives on Geekbench With 12GB of RAM and This MediaTek SoC
  5. Realme 15T With 50-Megapixel Selfie Camera Debuts in India: See Price
  6. Realme 15T 5G India Launch Today: All You Need to Know
  7. Apple Hebbal: First-Ever Apple Store in Bengaluru is Now Open
  8. Su From So OTT Release Date is Here! Know all the Details
  9. Apple Marks iPhone 8 Plus as Vintage Alongside These MacBook Models
  10. OnePlus 15 Will Reportedly Arrive With an In-House Camera Engine
  1. BCCI Says Crypto, Real Money Gaming Platforms Can’t Bid for Team India’s Title Sponsorship
  2. Scientists Discover Hidden Mantle Layer Beneath the Himalayas Challenging Century-Old Theory
  3. Astronomers Propose Rectangular Telescope to Hunt Earth-Like Planets
  4. Microsoft Testing Native Clipboard Sync Feature to Share Text Between Windows PCs, Android Devices
  5. Su From So OTT Release: When and Where to Watch This Kannada-Language Horror-Comedy Online
  6. Sennheiser Momentum 4 Wireless 80th Anniversary Edition Launched in India With Up to 60 Hour Battery Life
  7. Call of Duty Film Adaption Said to Be a 'Priority' at Paramount, Negotiations on to Acquire Rights
  8. Cannibal Solar Storm May Trigger Auroras as Powerful Geomagnetic Storm to Hit Earth Soon
  9. Apple's iPhone 8 Plus Listed as Vintage Product Ahead of iPhone 17 Launch, 11-Inch MacBook Air Now Obsolete
  10. Hidden Reason Behind Portugal’s Deadly Earthquakes Finally Explained
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.