Security experts in Hong Kong last week succeeded in taking down a key component of the Koobface bonnet, only to witness the system popping up in China.
The Koobface FTP grabber component uploaded stolen FTP user names and passwords to the remote server, which was under the control of cybercrooks. These stolen login credentials gave a pass into corporate networks and valuable data before the server was taken down last week, largely thanks to the efforts of the Hong Kong Computer Emergency Response Team Coordination Centre (HKCERT).
Full story @ The Register