The InformationWeek -- Blogs
Welcome Guest. | Log In| Register | Membership Benefits

Security

Topics:   Security

  • Email this page E-mail this page
  • Print this page Print this page
  • Bookmark and Share
  • icon

Targeted Attacks Keep Rolling


Posted by George Hulme, Feb 4, 2009 09:31 PM

There's a stealthy Trojan, named Bankpatch.com, that is circulating in Denmark. Unlike most Trojans, which aim to grab information from wherever they can, this one is targeting specific banks.


According to this Malicious Code Symantec blog post, this Trojan first surfaced in 2007, and the most recent .C version arriving in August of last year. The malware is targeting only certain banks:


However, the life of the threat continues today as the authors continue to distribute the threat and update plug-in modules that target specific banks. Most recently they’ve seen some success in Denmark deploying modules specifically focused on obtaining online banking credentials for numerous Danish banks. While Symantec is continuing deeper analysis of the threat’s latest actions and modules, we wanted to provide a high-level overview of the threat.

Here's how Eric Chien describes how Bankpatch works:

Usually Bankpatch will arrive via a popular means of infection such as Web pages hosting exploits against Internet Explorer and third-party browser plug-in vulnerabilities. Once executed on the machine, Bankpatch will add code to multiple Windows system files and patch key routines so that when these routines are executed, execution is redirected to the injected code.



Bankpatch not only injects its code into these system files to hide itself but also uses them as a trigger mechanism to perform additional actions. For example, Bankpatch adds code and patches wininet.dll, which provides client network functionality. This allows Bankpatch to track when Internet Explorer is being used.



When a user begins a browsing session, Bankpatch will contact one of its command-and-control servers. Bankpatch first sends system information and then receives instructions. Currently, many of these command-and-control servers appear to be down.



Typically, additional DLLs are downloaded, including BHOs (Browser Helper Objects), which are loaded into Internet Explorer. These BHOs are customized to target certain online banking systems and proceed to steal users’ online banking information. These BHOs will be detected as Infostealer.Nadebanker.

These types of targeted attacks can be much more difficult to spot. Couple that with the fact that they can be clandestinely inserted onto the systems of Web surfers doing nothing more than visiting what they believe to be "safe" sites makes the situation only worse.

We covered Trojan attacks targeting specific organizations, such as the South Korean military and similar attacks hitting U.K. government agencies and companies.

« Palm Pre In March? | Main | How Common Are Fake Reviews? »



Sign Up Now
For InformationWeek News Alerts




This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.




 
 

  1. Think Parallel 2010, Five Years of Multicore
  2. It's All In the Strategy, It's All About the Design
  3. How To Do Parallelism Without Getting Egg On Your Face


Join The InformationWeek Group On LinkedIn


  1. Flop Or Not, Nexus One Headed To AT&T
  2. Do SSDs Belong In Laptops?
  3. Why Microsoft Is The New Apple


  1. Google Nexus One Coming To Sprint
  2. AMD Announces Opteron 6100 Partners
  3. Hospital Supply System Improving Bill Accuracy
  4. Cloud Connect: Grappling With Economics
  5. Google Builds Microsoft Exchange Escape Route
  6. Cisco Accelerates Borderless Networks

 

  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag

  DECEMBER 2008
NOVEMBER 2008
OCTOBER 2008
SEPTEMBER 2008
AUGUST 2008
JULY 2008
JUNE 2008
MAY 2008
  APRIL 2008
MARCH 2008
FEBRUARY 2008
JANUARY 2008
DECEMBER 2007
NOVEMBER 2007
OCTOBER 2007
SEPTEMBER 2007