New Worm Sniffs for Paypal Information

CYBERSPACE – A new worm variant identified last week that targets Microsoft products also includes a new feature rarely seen in worms – it monitors network traffic searching for passwords and Paypal account information, according to network security firm Trend Micro.

Identified Sept. 8, the new variant of the SDBot Worm takes advantage of vulnerabilities in Microsoft operating systems and installs a Trojan horse that potentially allows an attacker to gain access to systems, as well as a network packet sniffer that searches for words like, “login,” “auth,” and “paypal.”

"If the Trojans described by Trend can successfully transmit the filter’s packet captures back to the owner they are going to cause problems well beyond typical bot infestation issues,” said Patrick Nolan of the Internet Storm Center, an organization devoted to analyzing Internet worms.

Designated SDBot.UH or “Bling.exe,” because of the filename under which it spreads itself, the worm employs a variety of transmission mechanisms and allows attackers to connect to infected machines, execute files, delete security logs and even watch users if they have a webcam attached to their computer.

Trend Micro warns that the worm can also perform distributed Denial of Service attacks against random IP addresses and attempts to steal CD authorization keys for computer games.

Network sniffers, usually employed by network administrators to diagnose problems, can also be illicitly installed and used to monitor information that travels through the network.

Rich Miller of British internet services company Netcraft says that although sniffers are notoriously hard to detect because they gather information instead of transmitting it, a few programs exist that can alert users to someone listening in on their electronic transmissions.

Trend Micro notes that the new SDBot variant uses the carnivore network sniffer, originally developed by the FBI to monitor suspects’ email. Trend is also reporting that the amount of computers infected by the new variant is low, but both the damage and distribution potential are high.

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Florida Attorney General Dismisses AV Suit Against Segpay

The Florida attorney general’s office on Monday agreed to dismiss claims against payment processor Segpay in a lawsuit over alleged noncompliance with the state’s age verification law.

FTC Weighs Reboot of 'Click to Cancel' Rulemaking Process

The Federal Trade Commission has invited public comments on a petition to renew trade regulation rulemaking concerning negative option plans, after a federal court previously vacated a “click-to-cancel” rule aimed at making it easier for consumers to cancel online subscriptions.

VRPorn.com Releases 2025 'Annual Report'

VRPorn.com has released its Annual Report, highlighting its audience favorites from throughout 2025.

MrPornGeek Launches 'Visibility Boost' System

MrPornGeek has introduced a new paid visibility boost feature designed to temporarily increase advertiser exposure across select sections of its platform.

New Federal Bills Aim to Repeal Section 230

Members of Congress this week introduced two bills calling for the repeal of Section 230 of the Communications Decency Act, which protects interactive computer services — including adult platforms — from liability for user-generated content.

RM11 Joins Pineapple Support as Supporter-Level Sponsor

RM11 has joined the ranks of over 70 adult businesses and organizations committing funds and resources to Pineapple Support.

Mark Spiegler Named XBIZ Talk Guest for 2026 LA Conference

XBIZ is pleased to announce that famed talent agent Mark Spiegler, impresario of the Spiegler Girls agency, will join an exclusive talk session at XBIZ 2026, the latest edition of North America’s largest adult industry conference, set to take place Jan. 12-15 at the Kimpton Everly Hotel in Hollywood.

Gataca Introduces Passkey Integration

Spain-based age verification provider Gataca has debuted its new passkey integration.

GloryPay Announces New Financial App

European fintech company GloryPay has announced the launch of its financial app for industry members.

Creator of Hentaied, Parasited Launches New Site 'MonsterPorn'

Romero Mr. Alien, the creator of Parasited and Hentaied, has launched new paysite MonsterPorn.com.

Show More