Keyloggers & Password Stealers :: Demystifying Spyware/Malware Security Series - Part 5

Keyloggers & Password Stealers

Overview

In writing this part of the security series it seemed appropriate that a good beginning would be to touch on a recent occurrence (August 2005) where Sunbelt Software malware researchers stumbled across a hidden server. This server, connected to the Internet, was collecting personal data from the computers of users that had been victims of having a key logging trojan program clandestinely installed on their machine.

I included here the audio interview that was conducted with Alex Eckelberry who is president of Sunbelt Software, as it really brings forth the dangers present on the Internet as professional criminal entities continue to setup and grow their operations.

The Eckelberry interview has several breaks of static for which we apologize. Please overlook these. We believe the message here is well worth it.
Play Eckelberry Interview (MP3 format - Opens new window)

As Alex Eckelberry reveals in the interview at the base of many of the dangers is not having in place a security procedures program such as making sure all current patches, like those released by Microsoft every month, are applied on a timely basis.

The Threat In A Nutshell

Keyloggers, which do exactly what you would surmise given the descriptive name, have become become one of the greater threats among the various methods of electronic crime on the Internet.

Once installed on a target system the key logging program collects a record of all the keystrokes made on a machine and typically stores that to a hidden file. This file is then periodically transmitted to another machine over the Internet.

Criminal groups behind the scheme collect the data and look for such sensitive information as credit card numbers, financial institution login names and passwords and similar information that may be used for identity theft or to conduct fraudulent financial transactions.

Keyloggers - From Installation to Personal Data Capture

To Be Continued