UK Insecurity experts Prevx has taken the unusual step of naming and shaming the victims because only one of them admitted that it had been turned over.
According to Reuters, the victims included consulting firm Booz Allen, Unisys, HP, satellite network provider Hughes Network Systems and the US Department of Transportation.
Only Unisys acknowledged that viruses had been detected and removed from two PCs but claimed that no data had been leaked.
However, Prevx said the malware uses a program named NTOS.exe that probes PCs for confidential data, then sends it to a Web site hosted on Yahoo.
The crackers have set up several "sister" Web sites that are collecting similar data from other squadrons of malware.
Prevx downloaded the data from the Web site used by the crackers and provided it to investigators from the FBI's Law Enforcement Online, or LEO, programme.
The malware wasn't recognised by existing antivirus software. More here. ยต