On CBS MoneyWatch: 6 things NOT to do on Twitter, Facebook
BNET Business Network:
BNET
TechRepublic
ZDNet

January 14th, 2008

Symantec: Trojan has 400 banks on its hitlist

Posted by Larry Dignan @ 11:56 am

Categories: Exploit code, Symantec, Viruses and Worms, Vulnerability research

Tags: Bank, Symantec Corp., Attacker, Trojan Horse, Spyware, Spyware, Adware & Malware, Security, Viruses And Worms, Larry Dignan

A Trojan dubbed Silentbanker targets more than 400 banks including the household names in the U.S. and other financial institutions abroad and hangs in the background to intercept transactions with two-factor authentication, according to researchers at Symantec.

In a day full of the usual Trojan attacks (they all sort of look alike after awhile) the sheer versatility of Trojan.Silentbanker is notable. Symantec researcher Liam OMurchu writes in a blog post:

The ability of this Trojan to perform man-in-the-middle attacks on valid transactions is what is most worrying. The Trojan can intercept transactions that require two-factor authentication. It can then silently change the user-entered destination bank account details to the attacker’s account details instead. Of course the Trojan ensures that the user does not notice this change by presenting the user with the details they expect to see, while all the time sending the bank the attacker’s details instead. Since the user doesn’t notice anything wrong with the transaction, they will enter the second authentication password, in effect handing over their money to the attackers. The Trojan intercepts all of this traffic before it is encrypted, so even if the transaction takes place over SSL the attack is still valid. Unfortunately, we were unable to reproduce exactly such a transaction in the lab. However, through analysis of the Trojan’s code it can be seen that this feature is available to the attackers.

Silentbanker was reported by Symantec last month but deemed very low risk at the time. Now Symantec reckons Silentbanker may have more mojo.

Symantec notes that the Trojan adapts based on what it needs. It tries the easiest attack vector and then works up to the more difficult approaches. In other words, the Trojan.Silentbanker cribs whatever it needs–cookies, passwords, certificates, HTML–to get the goods.

While this Trojan is only targeting one bank in a “classic man-in-the-middle” attack it’s capable of taking any passwords for multiple services. Toss in the ability to download updates and collect referrals for redirecting you to sites and this pup is quite versatile.

See the Symantec blog for the code and other details.

Larry DignanLarry Dignan is Editor in Chief of ZDNet and Editorial Director of ZDNet sister site TechRepublic. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 13 Talkback(s)
And as usual...
...we are not given a list of the affected sites. Why even bother to report these things if you're not going to disclose which bank sites we need to steer clear of?... (Read the rest)
Posted by: Ginevra Posted on: 01/15/08 You are currently: a Guest | | Terms of Use
The fact that...  BitTwiddler | 01/14/08
Reason 9765 not to use Windows  DarthRidiculous | 01/14/08
The question becomes, will you ever learn?  GuidingLight | 01/14/08
Sux to be you...  Confused by religion | 01/14/08
Larry...  D. T. Schmitz | 01/14/08
Umm...this shouldn't take long to put a stop to.  techboy_z | 01/14/08
Not as simple as that  JimbobH | 01/15/08
A security tip.  TripleII | 01/14/08
Good Tip  BanjoPaterson | 01/15/08
Good Second Link, too (nt)  BanjoPaterson | 01/15/08
H4t3rz need not apply  piratetwins@... | 01/15/08
It uses the biggest Windows exploit in the world...  NonZealot | 01/15/08
And as usual...  Ginevra | 01/15/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline