Hackers Lock Zeus Crimeware Kit with Windows-Like Anti-Piracy Tech

The newest version of Zeus, a do-it-yourself crimeware kit responsible for millions of dollars in losses by consumers and businesses, comes with anti-piracy provisions similar to those used by Microsoft's Windows, a researcher said today.

By Gregg Keizer on Mon, March 15, 2010

Computerworld — The newest version of Zeus, a do-it-yourself crimeware kit responsible for millions of dollars in losses by consumers and businesses, comes with anti-piracy provisions similar to those used by Microsoft's (MSFT) Windows, a researcher said today.

'Kneber' Botnet Attacks PCs Worldwide: FAQ

And that's a good thing.

Like Windows, Zeus 1.3 ties itself to a specific computer using a key code based in part on the machine's hardware configuration, said Kevin Stevens, a security researcher with Atlanta-based SecureWorks, and a co-author of a report on Zeus published last week. "It's just like a Windows license," said Stevens as he explained how the key code is generated.

After launching the Zeus Builder kit -- which sells for between $3,000 and $4,000 in its most basic configuration -- the software generates a hardware ID based on the PC's components as well as other factors, including the operating system's version number, said Stevens. That ID is then forwarded by the criminal customer to the seller of the program, who in turn cranks out a product activation code necessary to begin using the toolkit.

There is one major difference between the product activation practiced by Microsoft and what's used by Zeus, however. Although Microsoft will allow both minor and major changes to the hardware -- the latter may require a phone call to convince a support representative to issue another activation code -- there's no such protection for Zeus buyers. Even a small modification to the PC's hardware can prevent Zeus Builder from running. "You could request another [activation] code from the person who sold it to you, but there's no guarantee you would get one. The seller could say, 'I already have your money, pay for another.'"

The copy protection technology was added for obvious reasons, the same ones Microsoft cites when it explains why it regularly updates Windows Activation Technologies (WAT), better known by its earlier name of Windows Genuine Advantage (WGA). "This was definitely done to keep people from pirating the software," said Stevens, who noted that the previous versions of Zeus had been widely copied, tweaked and sold by others. "There have been a lot of Zeus [kits] hacked up."

Zeus 1.2, for example, only had a copyright disclaimer and a unique ID. If that ID was found on other copies in circulation, the malware seller might threaten to shut off sales to the buyer who had purchased, and likely leaked, the legitimate edition, said Stevens.

"It was a little like controlled pirating," he added. "[Zeus] 1.2.4.2 would come out, and then it would leak for a few months. Then 1.2.7.19 would come out and that would leak around for a couple of months."

Continue Reading

Originally published on www.computerworld.com. Click here to read the original story.

Apple

Get up to speed on Enterprise 2.0.

Learn More »
Loading...
Most Recent Windows 7 Stories
Learn how Dell helped a leading business services firm complete an enterprise-wide Windows 7 migration.
This research provides necessary steps to prepare for Windows 7 and ensure a successful migration with adequate operating system (OS) support.
Microsoft Windows 7 overwhelmingly met the requirements and showed improved performance and stability compared with Microsoft Windows XP.
Reducing the cost of deployment will significantly reduce the total cost of ownership - especially in combination with cost-saving features in Microsoft Windows 7.
Read this Case Study to see how Citrix® XenDesktop", Enterprise Edition was able to stream a single operating system image to all devices using single instance management.
This paper provides a total cost of ownership (TCO) assessment framework and analysis of further TCO reduction opportunities.
Windows 7 Upgrade Best Practices for SMBs
The Fast Track to Windows 7
What is the best way to integrate Windows 7 and exploit the many new, business-critical features it has? This Webcast probes a most compelling path to Windows 7 migration.
This Webcast discusses the highly scalable, superior IT optimization and workload consolidation that System z deliv...
Join Lee Weiner, Director, Support and Collaboration Technologies, LogMeIn, and guest speaker Ben Grey, Senior Anal...
Virtualization is not just for large enterprises. This expert video roundtable explains how to get started with a c...
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Resource Center