The sniffing capabilities of the new Worm-SDBot were documented by Trend Micro, and include a list of phrases associated with logins for network administration or Paypal accounts. “If the trojans described by Trend can successfully transmit the filter’s packet captures back to the owner, they are going to cause problems well beyond typical bot infestation issues,” according to the Internet Storm Center.
Malicious sniffers can be difficult to detect because their activity involves collecting packets, rather than transmitting them. Checking to see whether a network card is set in promiscuous (sniffing) mode is a common approach for users concerend about their own machines. Tools for detecting snifffers elsewhere on a network include Sentinel, AntiSniff.