Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

11/16/2017
02:00 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Terdot Banking Trojan Spies on Email, Social Media

Terdot Banking Trojan, inspired by Zeus, can eavesdrop and modify traffic on social media and email in addition to snatching data.

When is a banking Trojan more than a banking Trojan? When it can be used for cyberespionage.

Terdot, discovered by researchers at Bitdefender, can be used to view and modify traffic on email and social media platforms in addition to collecting victims' financial information. It can also steal credentials, inject HTML code on visited Web pages, and download and execute files.

The malware derives inspiration from the 2011 source code leak of the Zeus banking Trojan. It's not uncommon for banking Trojans to share similarities, however, and Zeus isn't the first to have its code made public. This has also happened with the Mirai, KINS, and Carberp malware families.

Bitdefender first spotted Terdot in October 2016, says senior e-threat analyst Bogdan "Bob" Botezatu. It performs the main functionalities of a banking Trojan: Terdot arrives in a malicious email with a button disguised as a PDF link. When clicked, it infects a machine and creates a Web proxy to modify transactions. Any data that victims send to a bank is intercepted by Terdot and modified in real-time, and the malware intercepts and modifies the bank's response.

The malware packs capabilities enabling hackers to collect far more than financial data. Because it lives in the browser, Terdot has unrestricted access to whatever is posted via that browser.

"The Web proxy is also instructed to steal sensitive information from the computer," says Botezatu. "It's not going after money; it harvests cookies from logged-in sessions and credentials for email accounts and social network accounts."

Terdot uses a chain of droppers, injections, and downloaders to protect the payload. It can bypass restrictions imposed by TLS by generating its own Certificate Authority and creating certificates for every domain visited in a man-in-the-middle attack. By injecting itself into the browser process, it can monitor activity and inject spyware.

Targeted regions include the US, Canada, the UK, Germany, and Australia. Frequently hit websites include Canada's PCFinancial, Desjardins, BMO, Royal Bank, Scotiabank, and CIBC. Affected email providers include Microsoft's live.com, Yahoo Mail, and Gmail; social media platforms Facebook, Twitter, Google Plus, and YouTube.

Terdot is specifically instructed not to collect data from Russian social media platform VK, which suggests Eastern European actors may be behind it.

Detection and Defense

Botezatu says Terdot poses a significant risk to businesses because of the way it's delivered and the damage a Trojan could inflict. However, its social media interception module adds a consumer spin to the malware.

"I don't think the guys in accounting would spend too much time on Facebook," he notes.

Terdot is extremely difficult to detect and remove, he continues. "It has modules that ensure persistence. It injects itself into every process on that machine, and these processes act like a watchdog to one another."

Because Terdot uses both phishing and man-in-the-middle to attack, businesses with breach prediction systems to cover all attack vectors are better prepared to defend themselves, says Manoj Asnani, vice president of product and design at Balbix.

"It should be noted that most of today's detection solutions are single attack vector-focused," he says. "A multi-vector system is needed in this case - and would have proactively flagged users that are at risk of phishing, in addition to compromised or spoofed certificates."

Unexpected Trend

This discovery is part of a growing trend of malware targeting financial institutions.

"We have started to see the reemergence of banker Trojans," he explains, adding that they had previously experienced a heyday between 2012 and 2016. "But we could have sworn the trend was otherwise."

It's curious to see banking Trojans resurface because they require several players and are difficult to launch and monetize, unlike comparatively easy attacks like ransomware. Botezatu blames their return on earlier Trojan code leaks and oversaturation of the ransomware market.

To this point, researchers at Trend Micro recently discovered a new iteration of banking malware Emotet with a few changes to its original behavior. This version of Emotet has been updated to evade detection and analysis; for example, it swapped its RunPE dropper for a Windows API to make it harder to find. Another anti-analysis tactic is checking when the scanner monitors activities to evade detection. It can also detect when it's inside a sandbox.

Related Content:

Join Dark Reading LIVE for two days of practical cyber defense discussions. Learn from the industry’s most knowledgeable IT security experts. Check out the INsecurity agenda here.

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
SOC 2s & Third-Party Assessments: How to Prevent Them from Being Used in a Data Breach Lawsuit
Beth Burgin Waller, Chair, Cybersecurity & Data Privacy Practice , Woods Rogers PLC,  12/5/2019
Cybersecurity Team Holiday Guide: 2019 Gag Gift Edition
Ericka Chickowski, Contributing Writer,  12/2/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-19645
PUBLISHED: 2019-12-09
alter.c in SQLite through 3.30.1 allows attackers to trigger infinite recursion via certain types of self-referential views in conjunction with ALTER TABLE statements.
CVE-2019-19678
PUBLISHED: 2019-12-09
In "Xray Test Management for Jira" prior to version 3.5.5, remote authenticated attackers can cause XSS in the generic field entry point via the Generic Test Definition field of a new Generic Test issue.
CVE-2019-19679
PUBLISHED: 2019-12-09
In "Xray Test Management for Jira" prior to version 3.5.5, remote authenticated attackers can cause XSS in the Pre-Condition Summary entry point via the summary field of a Create Pre-Condition action for a new Test Issue.
CVE-2019-19647
PUBLISHED: 2019-12-09
radare2 through 4.0.0 lacks validation of the content variable in the function r_asm_pseudo_incbin at libr/asm/asm.c, ultimately leading to an arbitrary write. This allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted input.
CVE-2019-19648
PUBLISHED: 2019-12-09
In the macho_parse_file functionality in macho/macho.c of YARA 3.11.0, command_size may be inconsistent with the real size. A specially crafted MachO file can cause an out-of-bounds memory access, resulting in Denial of Service (application crash) or potential code execution.