Zeus Trojan steals $1 million from U.K. bank accounts

15
Vote


Consumers and businesses in Great Britain have lost more than $1 million so far this summer from a Trojan that is infecting their computers, prompting them to log into their bank accounts, and then is surreptitiously transferring money to scammers in other countries, security researchers said on Tuesday.

About 3,000 bank accounts were found to be compromised at one financial institution, which was not identified, according to a white paper released by M86 Security.

The multilevel scheme uses a combination of a new version of the Zeus keylogger and password stealer Trojan, which targets Windows-based computers and runs on major browsers, and exploit toolkits to get around anti-fraud systems used at bank Web sites, the report found.

Bank sites that offer two-factor authentication, such as one-time passcodes and ID tokens, are ineffective because the malware has taken over the browser after the victim has logged into the banking site, Bradley Anstis, vice president of technology strategy at M86 Security, told CNET.

“This latest iteration of Zeus is dedicated to online banking,” and is bringing malware to a new level of technical sophistication, Anstis said. The Trojan uses encrypted communications between the infected computers and the command-and-control servers and performs illegal online banking transactions,” he said. M86 Security is working with law enforcement.

It appears to works similarly to the URLZone bank Trojan reported by Finjan a year ago that targeted German bank customers.

Here’s how the latest online scam works.

A computer user is compromised by either visiting a legitimate Web site that is secretly hosting the malware, or a site designed to host the malware, or a legitimate site hosting the malware in an advertisement. The primary attack came through malicious advertisements, including ads delivered by Yahoo’s Yieldmanager.com, the report said.

The malware redirects a Web surfer to an exploit kit, either the Eleonore Exploit Toolkit or the Phoenix Exploit Toolkit, that then exploits a vulnerability on the surfer’s computer and drops the Trojan on the machine. The Eleonore Exploit Toolkit includes exploits for vulnerabilities in Adobe Reader, Java, and Internet Explorer, among others.

“The initial infection where the exploit kit compromised the victim’s machine used a number of vulnerabilities that we list in the paper, one of those was an IE vulnerability that affected IE v6 & v7,” Anstis said. “However that was only one of the six or so vulnerabilities that could have been used for this initial infection. The exploit kit tests the victim machine for each one in order to get a successful infection.”

While more than 280,000 compromised computers were running some variant of Windows, there were about 3,000 Macs running the exploit kit that were part of the botnet, along with about 300 PlayStations and seven machines running Nintendo Wii, the report found.

The Trojan contacts a command-and-control server located in Eastern Europe to get instructions that sit on the victim’s computer, waiting for the opportunity to act.

When the user accesses his or her bank Web site, the Trojan transfers the log-in ID, date of birth, and a security number to the command-and-control server. Once the user accesses the transactional section of the bank Web site, the Trojan receives new JavaScript code from the outside server to replace the original bank JavaScript used for the transaction form.

When the user interacts with the transaction form for legitimate business, the Trojan works behind the scenes to manipulate the transaction. First it checks the account balance and if it is over a certain amount it will determine how much to steal within a limit so as not to trigger automatic fraud detection alarms.

The money is transferred to bank accounts of so-called “money mules,” typically innocent people recruited to use their own bank accounts to funnel money through. From there, the money is transferred to accounts in other countries that are controlled by the scammers.

Anstis declined to identify the bank whose customers were targeted. “Interestingly, this company did offer free security software,” he said. Either “the owners of the compromised accounts didn’t take them up (on the offer) or the software wasn’t effective.”

[Story Source] [Contest win Rs 1000-100,000 now]

This post was submitted by virendra kumar yadav.

Thanks to news.cnet.com
Related Posts
Bring back the hero

Bring back the hero

Salman Khan, who will soon be kicking butt on screen in Ready, says that he misses the stereotypical hero in Hindi cinema. Maybe that explains his choice of films like Dabang...
Sense of justice built into the brain, imaging study shows

Sense of justice built into the brain, imaging study shows

In the study publishing in the online open access journal PLoS Biology, the subjects' sense of justice was challenged in a two-player monetary fairness game, and their brain activity was simultaneou...
Ramdev plans fast-unto-death, seeking death penalty for graft

Ramdev plans fast-unto-death, seeking death penalty for graft

MUMBAI: Yoga guru Baba Ramdev Wednesday announced he will go on a fast-unto-death from June 4 in New Delhi to demand capital punishment for corrupt officials and recovery of black money stashed away i...
Govt to SC: Will tax black money

Govt to SC: Will tax black money

The Centre has informed the Supreme Court that black money stashed in tax havens abroad would be taxable income under the Direct Taxes Code Bill. It however, maintained its earlier stand on not reveal...
Visa racket busted, 4 held

Visa racket busted, 4 held

NEW DELHI: The anti-extortion cell of the crime branch of Delhi Police has busted a gang of cheats who duped people from Punjab of their money by promising to get Canadian visas for them.A team of pol...
 Kaavalan releases!

Kaavalan releases!

Ilayathalapathy Vijay, surmounting all odds has emerged triumphant. His Siddique directed Kaavalan has made it finally to cinema theatres today (Pongal day, January 15) in Tamil Nadu!After five days o...

Leave a Reply

 
We will keep You Updated...
Get Free Email Newsletter from VoteUpIndia Sign up for our free email newsletter. (Help?)
Read latest headlines in your favorite news reader
Follow VoteUpIndia  on Twitter Become a VoteUpIndia Fan on Facebook Subscribe to VoteUpIndia in Google Reader Add VoteUpIndia  to My Yahoo Add VoteUpIndia  to Netvibes Subscribe to Free Techie Buzz RSS Feed
Sponsors
Join Now !
Sponsors
Featured Video
Recent Posts

Woman robs her own home to start beauty parlour

Woman lodges false complaint of robbery, bruises self to make it seem real, blames brother; cops...

Bookie worth Rs 4,000 cr arrested for IPL betting

Cops nabbed five bookmakers, including three of country's top bookies, accepting bets on an IPL...

Abhishek will take time to recover: Big B

September 14, 2011, (Sawf News) - Abhishek Bachchan sustained minor injuries - a small cut above the...

Imran Khan files suit against drinking age

Actor Imran Khan Wednesday filed a public suit in the Mumbai High Court against raising the age limit...

Rakhi eyes Baba’s virginity!

Mumbai: The tale of baba and the babe seems to be getting spicier by the day. Impolite it may appear...
Recent Comments
i think it helps relationship because you can talk to that person though the internet
i really luv especially when rehan goes 80 yrs back and discussion in meera and rehan .also story of meera is really sensitive .i lo
i really luv this movie i luv it best excellent, fabolous ever i watched .tia bajpayee is really darling in her first looks in scene
Try to post good n interesting news ..... v dnt published any spam !!
i am submiting your site link plz post my site link
Tag Cloud