Anonymous tricked into installing Trojan
Summary: Two months ago, an unknown attacker slipped in a Zeus-infected version of Slowloris into the list of DDoS tools that Anonymous has been distributing to its supporters, according to Symantec.
Update: Anonymous reacts to Symantec Trojan report
Anonymous supporters who willingly used their PCs to participate in the group's Distributed Denial of Service (DDoS) attacks may have unknowingly handed over their personal e-mail and banking information in the process. In January 2012, an unnamed attacker took Slowloris, one of the DDoS attack tools popular with Anonymous supporters, and rigged it to include the Zeus Trojan. The individual copied and pasted an original Anonymous Pastebin entry offering the actual tool and replaced the download link with his own infected version. It just so happened that this post went viral among Anonymous supporters. To this day, it is still being shared on Anonymous blog posts and via Twitter.
If you haven't heard of Zeus, it's a Trojan horse that steals banking information via two methods: man-in-the-browser keystroke logging and Form Grabbing. First identified in July 2007, Zeus is spread mainly through drive-by downloads and phishing schemes, and its various variants have already infected hundreds of thousands of PCs. Now it looks like Zeus has been used to steal financial data from Anonymous supporters.
The story begins on January 19, 2012, when authorities raided Megaupload, and Anonymous hackers retaliated by taking down DOJ, RIAA, MPAA, Universal Music websites, among others. That day, Anonymous released a list of several different DDoS attack tools under a guide referred to as "Tools of the DDoS trade" and "Idiot's Guide to Be Anonymous." Under "Operation Megaupload," supporters were urged to download one of the tools, which would enable them to contribute to the DDoS attacks with their own computers.
In the following weeks, the compromised DDoS tool may have also been used in attacks on several U.S. government websites to protest the government's support of the Anti-Counterfeiting Trade Agreement (ACTA) and against Syrian government websites. Since the modified Slowloris link was on the list, countless people who thought they were simply supporting Anonymous' mission were actually compromising their own financial security.
Security firm Symantec has the details:
An attacker took a popular PasteBin guide, used by Anonymous members for downloading and using the DoS tool Slowloris, and modified it. In this modified version, the attacker changed the download link to a Trojanized version of the Slowloris tool with matching text. Later that same day, a separate Anonymous DoS guide was posted on PasteBin which included links to various DoS tools. Slowloris was included in this list of tools—the Trojanized version copied from the modified guide.
Once downloaded, installed, and executed, the infected version of Slowloris uses the Zeus botnet client to send login credentials and cookies to the criminal's C&C server. In typical Trojan fashion, the botnet also orders the Slowloris tool on the infected user's computer to attack Anonymous targets, ensuring that the victim still sees the tool do what he or she expects it to.
It's not clear how many Anonymous supporters used the infected Slowloris, so there's no way to gauge how many were (or still are) unknowingly transmitting their own bank account data to a remote server. Security companies have previously warned Internet users backing Anonymous not to participate in the DDoS attacks because they are breaking the law. Now, Symantec says they "may also be at risk of having their online banking and email credentials stolen."
Update: Anonymous reacts to Symantec Trojan report
See also:
- Anonymous launches 'Operation Global Blackout', aims to DDoS the Root Internet servers
- Weekend Anonymous attacks bring down major websites
- How Anonymous took down the DoJ, RIAA, MPAA and Universal Music Websites
- Anonymous is not attacking Facebook today
- Profile of a failed Anonymous attack
- How to try to stop DDoS Attacks
Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.

Talkback
No honor among thieves
On the other hand..
fdfdd
Wholesale lable Reflective Safety Vest http://www.chinawholesaletown.com/wholesale-Patient-Care/ Inflatable Products
CD Holde Wholesale USB Flash Drive http://www.chinawholesaletown.com/wholesale-Cap/ Writing Instrument
Wholesale Golf Products Flash Gift http://www.chinawholesaletown.com/wholesale-Writing-Instrument/ Arts Crafts
Wholesale Playing Card Wholesale Wallet http://www.chinawholesaletown.com/wholesale-Keychain/ Pom Poms
Wholesale Mp3 Promotional Gifts http://www.chinawholesaletown.com/wholesale-Thermometer/ Bookmark
Wholesale Mobile Phone Consumer Electronics http://www.chinawholesaletown.com/wholesale-Poncho-Raincoat/ Men Beauty Care
Money Clip Wholesale Cards http://www.chinawholesaletown.com/wholesale-Scale/ Belt
Valentine Gifts Wholesale Halloween Gift http://www.chinawholesaletown.com/wholesale-Tie/ Muslim Products
Wholesale Ruler Valentine Gifts http://www.chinawholesaletown.com/wholesale-Hair-Products/ Crystal Gifts
Wholesale Coaster Wholesale Magnifier http://www.chinawholesaletown.com/wholesale-Camera/ Mirror
Wholesale Mug Wholesale Mat http://www.chinawholesaletown.com/wholesale-Shoes/ Toys
Wholesale Cup Wholesale First Aid Kit http://www.chinawholesaletown.com/wholesale-Safety/ Bottle Opener
Wholesale Pedometer Wholesale Bangle http://www.chinawholesaletown.com/wholesale-Gift-Box---Display/ Consumer Electronics
Wholesale iPod iPhone Muslim Products http://www.chinawholesaletown.com/wholesale-Pet-Supplies/ Helmet
Safety Products Patient Care Products http://www.chinawholesaletown.com/wholesale-Money-Bank/ Sport Support Products
Silicone Products Sport Items http://www.chinawholesaletown.com/wholesale-Lady-Beauty-Care/ Ashtray
Wholesale Tellurion Mouse Pad http://www.chinawholesaletown.com/wholesale-Scissors/ Thermometer
Wholesale TelePhone Wholesale Keyboard http://www.chinawholesaletown.com/wholesale-Speakers/ Binoculars
Wholesale Tie Wholesale Radio http://www.chinawholesaletown.com/wholesale-Candle/ Poncho Raincoat
Book Light Wholesale Glasses http://www.chinawholesaletown.com/wholesale-Bookmarks/ Silicone Products
Flash Gift Home Appliances http://www.chinawholesaletown.com/wholesale-Photo-Frame/ Halloween Gift
Wholesale Binoculars Wholesale Mirror http://www.chinawholesaletown.com/wholesale-Vase/ Promotional Gifts
Wholesale Clothing Wholesale Flag http://www.chinawholesaletown.com/wholesale-Wine-Set/ Ruler
Wholesale Scale Computer Accessories http://www.chinawholesaletown.com/wholesale-Poncho-Raincoat/ Automotive Products
Wholesale Whistle Wholesale Scale http://www.chinawholesaletown.com/wholesale-Pen/ Clothes Rack
Consumer Electronics Cleaner Products http://www.chinawholesaletown.com/wholesale-Sport-Support/ Bag
Coin Bank Photo Frame http://www.chinawholesaletown.com/wholesale-Garden-Decorations/ Gift Box
Bottle Opener Wholesale Mobile Phone http://www.chinawholesaletown.com/wholesale-Kitchenware/ Pedometer
Electrical Gifts Wholesale Socks http://www.chinawholesaletown.com/wholesale-Golf-Items/ Name Card Holder
Electroluminescent Wholesale Gift Bags http://www.chinawholesaletown.com/wholesale-Solar-Products/ Fishing Supplies
Promotional Items Wholesale Swimming Products http://www.chinawholesaletown.com/wholesale-Clap-Hands/ Flash Gift
Wholesale Magnifier Gift Box http://www.chinawholesaletown.com/wholesale-Tape-Measure/ Golf Products
Money Bank Tape Measure http://www.chinawholesaletown.com/wholesale-Health-Care-Products/ Album
Wholesale USB Products China Wholesale http://www.chinawholesaletown.com/wholesale-Tag---lable/ Manicure Set
Sport Support Products Wholesale Towel http://www.chinawholesaletown.com/wholesale-Gift-Bags/ Stress Ball
Wholesale Helmet Wholesale Dartboard http://www.chinawholesaletown.com/wholesale-Home-Appliances/ Scale
*BOOM*
BAH-HAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHA!!!!!
Sweet!
So kind of a case of reaping what they sow?
That's what I wondered
Most likely the latter
Forget law enforcement
LMAO - This is awesome
Still LMAO
Karma is a b*tch
Go Figure!
Dishonest or ignorant reporting...
But the cat is out of the bag
Hurtn?
Dishonest? Ignorant?
The Article also links to various others sources showing the response in the Anon community - providing some balance for a reader to make up their own mind.
Ignorant? Where's the ignorance in the story? Ignorant of what?
Honor amonst thieves....
Interesting turn of events, I wonder how Anonymous handle this.
FUD