Risk
2/28/2011
05:55 PM
George V. Hulme
George V. Hulme
Commentary
Connect Directly
RSS
E-Mail
50%
50%

Sophisticated Trojan Targets Some Banking Sites

S21sec, a Spanish information security firm, claims to have spotted a new Trojan with advanced infiltration and attack techniques.

S21sec, a Spanish information security firm, claims to have spotted a new Trojan with advanced infiltration and attack techniques.This Trojan, named Tatanga, like most banking Trojan, possesses man-in-the-browser capabilities, can inject malicious HTML code into many popular browser types. According to S21sec, the Trojan can conduct banking transactions in the background. The Trojan can display a fake balance, which the end user perceives as the real account balance, while their account is being fleeced.

"The trojan in question is rather sophisticated," the company posted in its research blog. "It is written in C++ and uses rootkit techniques to conceal its presence, though on occasion, its files are visible. The trojan downloads a number of encrypted modules (DLLs), which are decrypted in memory when injected to the browser or other processes to avoid detection by antivirus software," it continued.

Some of those libraries grab email addresses, encrypt and manage the malware's processes, remove other forms of malware on the machine, as well as block installed antivirus applications.

The Trojan can also grab user credentials during the session, including one-time-passwords. The malware relies on both technical attacks as well as social engineering tactics designed to walk users through a transfer they think is a demonstration transfer.

S21sec has a snippet of the Trojan's code on its site.

While the Trojan is currently targeting European banks, mainly in Spain, United Kingdom, Germany, and Portugal - these attacks rarely remain localized.

Unfortunately, according to the security firm, the anti-virus detection rate of this Trojan is currently very low.

For my security and technology observations throughout the day, find me on Twitter.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, September 16, 2014
Malicious software is morphing to be more targeted, stealthy, and destructive. Are you prepared to stop it?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2006-1318
Published: 2014-09-19
Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, Office 2004 for Mac, and Office X for Mac do not properly parse record lengths, which allows remote attackers to execute arbitrary code via a malformed control in an Office document, aka "Microsoft Office Control Vulnerability."

CVE-2012-2588
Published: 2014-09-19
Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Enterprise 6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, or (3) Subject header or (4) body in an SMTP e-mail message.

CVE-2012-6659
Published: 2014-09-19
Cross-site scripting (XSS) vulnerability in the admin interface in Phorum before 5.2.19 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVE-2014-1391
Published: 2014-09-19
QT Media Foundation in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with RLE encoding.

CVE-2014-3614
Published: 2014-09-19
Unspecified vulnerability in PowerDNS Recursor (aka pdns_recursor) 3.6.x before 3.6.1 allows remote attackers to cause a denial of service (crash) via an unknown sequence of malformed packets.

Best of the Web
Dark Reading Radio