Zeus leaks give tools to researchers, attackers

13.05.2011
The source code and a manual to the popular crimeware creation kit has been leaked, perhaps giving defenders additional tools to fight infections but also raising concerns that criminals may use the source code to create a rapidly expanding compendium of variants.

Nearly a week ago, copies of the source code to Zeus appeared on the Internet, . The release comes about the same time that a manual describing Zeus's functionality also appeared on the Web. While having access to the source code could be a boon to researchers, security professionals also worried that having access to the code could result in a spurt of innovation among criminals.

"It remains to be seen whether we see appearing over the next few days, weeks or even months," says Paul Wood, senior analyst with Symantec.cloud. "Of course, the ability then is for the other bad guys to take advantage of some of the technology that they don't have in their tool kit and build that into their own technology, because there are certainly a quite a lot of interesting features in the Zeus toolkit."

In 2004, the creator of the posted his code to the public. Soon after, Agobot variants skyrocketed, turning the code for the software into one of the largest families of malware detected on the Internet.

Zeus is already popular and is frequently used as the means to steal money from victims' bank accounts. Yet, the source code could help criminals create more variations on the source code, says Wood.

The release of the code comes around the same time as the publication of a manual for the software. In a tweet on Wednesday, Mikko Hyponnen, chief research officer for security firm F-Secure, highlighted .