ZeroHour
Kaspersky Securelistpublished ()ingested @Securelist

The next step in Trojan

highMalwareimportance 42
Full article315 words · extracted from securelist.com · click to collapse

Research

Research

15 Aug 2007

minute read

Recently I’ve been doing research in a rather interesting Trojan-Spy.Banker case.
It’s a multi-stage attack and unlike anything I’ve seen before.

First a machine gets infected with a Trojan-Downloader which has some spy functionality. It installs itself by patching two system files – kernel32.dll and wininet.dll.

This Trojan transmits URLs visited by the user to a malicious web server.
If the Trojan detects HTTPS traffic being submitted to the web server, the server instructs the Trojan to download a file. Of course, this file is another Trojan, this time designed to capture the HTTPS traffic, most notable HTTPS traffic from online banking sites. After a while the server instructs the Trojan to download yet another file.And this file will be a dedicated banker Trojan which correspondsd to the bank the victim uses.

Using the HTTPS traffic logger enables cyber criminals to create a dedicated banker Trojan for specific banks. In short, the sophistication of this attack is frightening. It’s tailored for optimum efficiency and bypassing security products. I had hoped that we wouldn’t see this kind of attack at least until next year, but there’s no real predicting malware evolution.

Combatting these new threats is going to be a challenge for all involved parties.

Latest Webinars
Reports

Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.

Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.

Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/the-next-step-in-trojan-spy-banker-evolution/30360/