24 Aug 2011
Hackers have infused an 18-month-old worm with Zeus financial malware to attack two-factor authentication and transaction signing systems used in online banking sessions.
Configurations of the Win32.Ramnit worm, captured and reverse engineered by Trusteer, were found to incorporate tactics from the Zeus financial malware platform. Zeus source code was published on the internet earlier this year.
Further reading
Trusteer researchers found the method used to configure Ramnit to target a specific bank is identical to the one used by Zeus. This allows fraudsters to easily port Zeus configurations to Ramnit.
According to the Symantec Intelligence Report for July, Ramnit accounts for 17.3 per cent of all new malicious software infections. Trusteer estimates tens of thousands of machines used for online banking are currently infected with Ramnit.
Ramnit, an old-school file-infection virus, was first detected in 2010 and targets EXE, SCR, DLL, HTML and other file formats. Its command and control servers in Germany are currently live.
"Unlike the past, when financial institutions had to defend against a limited number of malware platforms, attacks can now come from virtually any malicious software program, old or new," said Amit Klein, chief technical officer of Trusteer. "The malware distribution channel for fraudsters has increased in scale significantly."
Have your say on this article
Newsletters
Latest stories from Threats and Risks
You may also like
Threats and Risks jobs
Technology Patent Wars
Case studies from large organisations across all sectors
... And rich media, and flexible working, and peaks in traffic ...
Upcoming Events
Join us for this Computing web seminar, in which the Head of BI at the Co-operative Group Nick Colebourn will be explaining just how he reigned in the Group’s sprawling database estate and how significant savings were realised and data quality improved as a result.
Date: 31 May 2012
Time: 11:00 AM
Live June 13th 11:00am: Register now. During this web seminar we will be looking at the sorts of incidents that can bring data centres grinding to a halt and what can be done about them.
Date: 13 Jun 2012
Time: 11:00 am
Receive the latest jobs direct to your inbox
Are you being paid what you are worth?