Quick and short explanation of bank bots, for starters

rokitbayy

Professional
Messages
108
Reaction score
29
Points
28
Alright so i have decided to write a little about bank bots, aka botnets, like the commonly known ones as spyeye, zeus, citadel, ice 9 etc.

I will explain you their basic functions, what they are used for, and what you'll need to keep and maintain your own botnet. Its basically written for starters who're interested in this field.

What are these botnets used for?
They are used for many different purposes like gathering private details, logins to websites, credit card information, bank logins, paypal accounts etc.

If you can use a simple keylogger or any other RAT with keylogging function, why specifically go for botnet?
Thats because of the function called webinjecting. By injecting the browser's API, the botnet is then able to edit the original website the victim is viewing and show what you want the victim to see.
For example, you have zeus with chase webinject on it, and when your victim visits the bank's address www.chase.com, and enters his account login info (user id and password), a pop-up is displayed, blackening the background, asking for additional information like dob, ssn, cc details, etc as per your like.

What all is needed for running a botnet and maintaining it?
First of, you need a bulletproof VPS (shared or dedicated) or a fastflux server and a domain, recommended registration in offshore countries.

And depending on which botnet you choose, you'll need crypting. 1 crypt costs around $1 to $10 for each crypt. And you'll be needing to crypt every once in a while, for like a botnet with 10k bots, and you're running spyeye, I would recommend crypting your bin and updating it every 3-4 days, so that your bots don't die aka their AV detects your spyeye and removes it etc. But now new botnets like citadel have auto-crypting function, where it crypts the bin on its own and stays undetected. This way you save money on crypting.

A decent list of updated, working webinjects. You'll need this to gather additional and full information from the account logins of the banks or websites you want. So if you're looking after wells fargo and chase bank logins, you need to get webinjects for chase and wells fargo banks.

Will write more on 2nd post as when I have time, and images will be added. Any questions regarding botnet (of any type like spyeye, zeus, citadel) you can ask me here and I'll try my best to give you support.
 
I've been getting questions in PM, and have been giving support to members that way and also plan to continue it that way, so if you have any questions regarding botnet please pm me and I will try my best to help you out.
 
very good post rokitbay .. i never be interested in this of botnets or things like that but i think i wanna enter to this world.. if you can create or share whit me some manual or brief explication for a real begginer like .. i just work whit dumps..that is my world this is a new world for me.. i am interestd in work whit this

---------- Сообщение добавлено в 10:59 PM ---------- Предыдущее сообщение размещено в 10:58 PM ----------

well you get +1 from me.. in becaseu this is really helpfull for the board members
 
You're all very wellcome, soon will release full ENGLISH spyeye tutorial 1.3.48 + videos about how to "crack" the builder, upload the panels and get everything working and also basic explanations of quickly getting bots to your panel.
 
very nice sharing :)
+1 appreciate for it
will wait more explanation and videos
 
Can you explain the difference between public versions of botnets and paid versions? Also can you give a step by step to get botnet up and going, assuming vps is taken care of and botnet is public or bought.
 
Can you explain the difference between public versions of botnets and paid versions? Also can you give a step by step to get botnet up and going, assuming vps is taken care of and botnet is public or bought.

A public botnet has risk of containing a backdoor (means all the logs you collect will be sent to someone else too, or your bots. Can be any of them or both). Also detection ratio of a public botnet vs private one has big difference.

For example zeus is public, and if you crypt it FUD, it will be detected by AV in 1-2 days max. But citadel is a private bot, and if you crypt it FUD, it will be undetected for 1-2+ weeks.

Which botnet you want me to make tutorial of setup?
Zeus 2089
Spyeye 1345
Spyeye 1348
Carberp
Citadel
ICE 9
Andromeda
Adrenalin
Barakuda
list goes on
 
A public botnet has risk of containing a backdoor (means all the logs you collect will be sent to someone else too, or your bots. Can be any of them or both). Also detection ratio of a public botnet vs private one has big difference.

For example zeus is public, and if you crypt it FUD, it will be detected by AV in 1-2 days max. But citadel is a private bot, and if you crypt it FUD, it will be undetected for 1-2+ weeks.

Which botnet you want me to make tutorial of setup?
Zeus 2089
Spyeye 1345
Spyeye 1348
Carberp
Citadel
ICE 9
Andromeda
Adrenalin
Barakuda
list goes on

Spyeye, please.
 
Please note, if you want to make a deal with this user, that it is blocked.
1345 Spyeye would be nice!
 
Top