Next-Generation Banking Malware Emerges After Zeus 48
Batblue writes "The rumored combination of two pieces of advanced online banking malware appears to be fully underway after several months of speculation. What appears to be a beta version of a piece of malware that has bits of both Zeus and SpyEye is now in circulation, albeit among just a few people, said Aviv Raff, CTO and cofounder of Seculert. Seculert has published screen shots of the new malware, which has two versions of a control panel used for managing infected computers. One of those control panels resembles one in Zeus, and the other resembles that in SpyEye. Both of the control panels are connected to the same back-end command-and-control server, he said."
Safest Banking (Score:2)
Oh no! They're gonna get at the wad of money buried in the back yard! It may only earn the interest of worms, but at least its not funding wall street
Re: (Score:1)
The safest banking is to follow the law of God which the bankers should themselves be following. Pick up only enough for today--maybe enough for tomorrow or a few days. If you find yourself picking up enough for next season, next year, years to come, generations to come, then you're already doomed.
Re: (Score:2)
Your savings account money typically funds mortgages and small businesses. "Wall Street" runs on capital largely derived from the sale of stocks, and banks don't buy stock with their depositors' money.
Alternative link (Score:4, Informative)
Kreb's writeup is pretty good as well, not that anyone reads tfa.
http://krebsonsecurity.com/2011/02/revisiting-the-spyeyezeus-merger/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+KrebsOnSecurity+(Krebs+on+Security) [krebsonsecurity.com]
Re: (Score:2, Insightful)
why does Microsoft even allow malware to be installed on Windows 7 in the first place?
Your stupidity astounds me.
Comment from TFA (Score:3, Interesting)
Re: (Score:2)
Wow, that is a very interesting question. I would think that it would not be such a good idea to act in such an overt manor. The one issue I see is that some/most of the "command and control" servers are located in other sovereign countries...some of which are even friendly, so attempting to breach such machines could be construed as an attack on a sovereign nation.
Now with that, I believe that it is something that organizations such as the CIA or NSA should be doing this in a covert manor.
Re: (Score:1)
Congress can't do that, because it violates due process. We have to give "the bad guys" a trial. They are presumed innocent, until proven guilty.
Agreed. Violating due process is best left to the professionals [techdirt.com].
Rule of Thumb (Score:2)
Banking malware - wha ? (Score:1)
I see, it's either computer malware, Internet malware or now banking malware. How much PR effort must have gone into inserting that particular viral marketing meme into the blogosphere ..
Re: (Score:2)
It's just English. "Banking malware" is shorthand.
Use a Live DVD? (Score:2)
I'm starting to think I should try modifying an Ubuntu live DVD so it's preconfigured to ignore HDD and block out everything but my bank. I'd still have to save files to USB though.
Anyone have experience with Rapport? Is it some lightweight thing you just run when you want to access internet banking or is it some nuisance running all the time?
Use a Live USB (Score:1)
You can install a full working system to a USB device using the Ubuntu Live USB [wikipedia.org] creator. You can configure it so save your configuration to a separate partition and make it readonly using a physical read-write switch. Your session runs from memory and so is flushed at each reboot. There are various desktop environment available, one of the lightest is Lubuntu [slashdot.org]. Any business out there doing online Banking should produce their own customized Live CD and hand them out to their employees, there are various syste
Re: (Score:3)
USB sticks with "physical read-write switch" don't exactly grow on trees.
As far as I know only Kanguru and Imation(aka 3M) make them and Imation's USB Sticks are slow. Kanguru Sticks are hard to come by.
Is there such a thing as an inline USB write protect switch?
Re: (Score:2)
I looked them up.
$300 and total overkill.
If Kanguru can do it without bulk or a External power supply, isn't there something about the size of a USB stick that can do the same?
Re: (Score:2)
USB sticks with "physical read-write switch" don't exactly grow on trees.
As far as I know only Kanguru and Imation(aka 3M) make them and Imation's USB Sticks are slow. Kanguru Sticks are hard to come by.
Is there such a thing as an inline USB write protect switch?
Would an SD card in a reader respect the write protect switch? Both SD cards & USB readers for them are cheap & easily available.
Re: (Score:1)
Re: (Score:2)
Re: (Score:1)
i think the only good solution so far has been livecd (assuming bios is ok).
or using seperate, locked down, firewalled, etc.. computer only for banking.
Re: (Score:2)
The malware defeats your bank's measures by performing a man-in-the-middle attack. When you point your browser at your bank's website the malware steps in and it accesses your bank and sends you a copy of the page. You enter the details of your supplier but the malware substitutes their own account details. You then dutifully go through the security routine, unwittingly authorising the wrong account. iTAN is completely defeated by both phishing and man-in-the-middle, all it is any good for is against key lo
Re: (Score:2)
Re: (Score:1)
Man in the middle no no, you mean buffer overflow, Like this critical exploit from from 2005? http://www.eweek.com/c/a/Security/VMWare-Virtual-Machine-Security-Flaw-Very-Serious/ [eweek.com]
Or the 300 exploits starting on this page ? http://www.securityfocus.com/cgi-bin/index.cgi?o=0&l=30&c=12&op=display_list&vendor=VMWare&version=&title=ESX%20Server&CVE= [securityfocus.com]
Vming doent help, install patches, have intrusion prevention and early detection, have a measurement and hardening practice, have an AV and
Re: (Score:1)
Not true at all. All that is is cross site request forgery protection. Wont help you a single bit if the attacker substitutes his or her self as a payee and substitutes your remaining balance as the amount.
It Also would not help you if the transaction reponse page was a fake and the attacker collected a week's worth of your ITANS, how often does the average Germal banking customer call thier Bank? If the bank delivers electronic statments then, you will never see one showing fraud, and if they deliver physi
Re: (Score:1)
Right! just what the world needs, another *nix variant. Slaps forehead.
Re: (Score:2)
Or, why not just get a netbook, completely erase the hard drive and install your favorite Linux? Lock it down, image it and use it only for banking.
Banking only needs
Good thing I use a Credit Union (Score:2)