New Worm Sniffs for Paypal Information

CYBERSPACE – A new worm variant identified last week that targets Microsoft products also includes a new feature rarely seen in worms – it monitors network traffic searching for passwords and Paypal account information, according to network security firm Trend Micro.

Identified Sept. 8, the new variant of the SDBot Worm takes advantage of vulnerabilities in Microsoft operating systems and installs a Trojan horse that potentially allows an attacker to gain access to systems, as well as a network packet sniffer that searches for words like, “login,” “auth,” and “paypal.”

"If the Trojans described by Trend can successfully transmit the filter’s packet captures back to the owner they are going to cause problems well beyond typical bot infestation issues,” said Patrick Nolan of the Internet Storm Center, an organization devoted to analyzing Internet worms.

Designated SDBot.UH or “Bling.exe,” because of the filename under which it spreads itself, the worm employs a variety of transmission mechanisms and allows attackers to connect to infected machines, execute files, delete security logs and even watch users if they have a webcam attached to their computer.

Trend Micro warns that the worm can also perform distributed Denial of Service attacks against random IP addresses and attempts to steal CD authorization keys for computer games.

Network sniffers, usually employed by network administrators to diagnose problems, can also be illicitly installed and used to monitor information that travels through the network.

Rich Miller of British internet services company Netcraft says that although sniffers are notoriously hard to detect because they gather information instead of transmitting it, a few programs exist that can alert users to someone listening in on their electronic transmissions.

Trend Micro notes that the new SDBot variant uses the carnivore network sniffer, originally developed by the FBI to monitor suspects’ email. Trend is also reporting that the amount of computers infected by the new variant is low, but both the damage and distribution potential are high.

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

FSC Publishes Analysis of Federal Trade Commission Event Promoting AV

Free Speech Coalition (FSC) has published an analysis of a Federal Trade Commission (FTC) event held this week that promoted age verification among other forms of speech regulation.

GirlsDoPorn Owner Michael Pratt Pleads Guilty to Sex Trafficking

Michael Pratt, former owner of the rogue website GirlsDoPorn, pleaded guilty in the U.S. District Court for the Southern District of California on Thursday to sex trafficking and conspiracy to commit sex trafficking charges, according to a report by City News Service.

Master Nico Relaunches Site Through YourPaysitePartner

Master Nico has relaunched his official website through YourPaysitePartner (YPP).

Federal Judge Grants Partial Halt of Florida AV Law

The United States District Court for the Northern District of Florida, Tallahassee Division, has granted a preliminary injunction against HB 3, the state's age verification law, as a lawsuit filed by two online trade associations challenging the law makes its way through the courts.

Aylo Releases Statement on Suspending Access to Pornhub in France

Technology and media company Aylo, which operates adult sites including Pornhub, YouPorn, and Redtube, has released a public statement regarding its decision to block access to its sites in France.

Pineapple Support to Host Wellness Sessions at Bucharest Summit

Pineapple Support is hosting free group and one-on-one therapy sessions at Bucharest Summit, June 3-5.

Pornhub Blocks Access in France in Response to SREN Law

Pornhub parent company Aylo has opted to block access to its sites in France rather than comply with age verification requirements under the country’s Security and Regulation of the Digital Space (SREN) law.

ASACP Highlights Study on Parental Controls

The Association of Sites Advocating Child Protection (ASACP) is highlighting the results of a study on the underutilization of parental controls.

Sydney Screams Launches New Site Through Grooby's Blue.xxx

Sydney Screams has launched her new membership site, SydneyScreams.xxx, through Grooby's website management company Blue.xxx.

Mistress Mystii Is LoyalFans' 'Featured Creator' for June

LoyalFans has named Mistress Mystii as its Featured Creator for June.

Show More