Despite crackdown, Zeus bank-robbery malware still 'alive and kicking'

Summary:Microsoft's malicious software removal tool is disinfecting the Zeus malware (also called Zbot) from between 60,000 and over 100,000 unique Windows computers every month.

Despite a widespread industry effort to disrupt and shut down the Zeus malware gang, Microsoft's malicious software removal tool is still finding tens of thousands of machines infected with the notorious banker trojan every month.

According to Microsoft, the tool is disinfecting the Zeus malware (also called Zbot) from between 60,000 and over 100,000 unique Windows computers every month.  The disinfection utility is updated and released once a month on Patch Tuesday to clean Windows machines from the most prevalent malware threats.

follow Ryan Naraine on twitter

Here's the breakdown of MSRT Zeus disinfections for the last few months:

Month Count
March 103391
April 113814
May 60385
June 83555
July 61323
August 89994
"Yes, it's still around and kicking," says Microsoft's Matt McCormack.

"We're still seeing both distinct malware families out and about in the wild. Between the two, we're finding that they're responsible for a significant amount of the e-commerce-related fraud happening at any given time," McCormack added.

In August, Microsoft sneaked in a new definition signature for Zeus into the cleaning utility and discovered and removed about 90,000 Windows machines infected with Zeus.

According to abuse.ch's Zeus tracker, there are about 220 command and control servers online at any given time.  The site monitors the about 700 servers hosting the botnet.

Topics: Malware, CXO, Operating Systems, Security, Software, Windows

About

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues. He is currently security evangelist at Kaspersky Lab, an anti-malware company with operations around the globe. He is taking a leadership role in developing the company's online community initiative around secure content managem... Full Bio

zdnet_core.socialButton.googleLabel Contact Disclosure

Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.

Related Stories

The best of ZDNet, delivered

You have been successfully signed up. To sign up for more newsletters or to manage your account, visit the Newsletter Subscription Center.
Subscription failed.