Experts sound alarm on Silentbanker Trojan

Powered by SC Magazine
 

Researchers have uncovered a new banking Trojan which steals user data from more than 400 banks worldwide..

Trojan.Silentbanker intercepts account information, redirects traffic to phishing sites, and even alters transactions to send money to the attacker's bank account.

The long list of targets include banks in the US, UK, Ireland, Spain and France.

"The scale and sophistication of this emerging banking Trojan is worrying, even for someone who sees them on a daily basis," wrote Symantec researcher Liam O'Murchu in a company blog.

The most troubling feature of the Trojan is its ability to perform man-in-the-middle attacks to intercept and alter data travelling between the browser and the bank.

This allows the Trojan to modify data and reroute money to another account without the user's knowledge.

The malware also has the ability to steal and upload account data, change DNS settings and reroute users to phishing sites.

O'Murchu noted that the Trojan can display more than 600 pornographic URLs, which he suspects is designed to raise the Trojan's author referral payments.

The current attacks may be just the beginning, however. O'Murchu said that the Trojan is constantly updating itself, checking for new configuration files several times a day.

Symantec urged users to protect against the Trojan by keeping antivirus software up to date. Administrators can also configure firewalls to block the URLs to which the Trojan connects.

Copyright ©v3.co.uk


Experts sound alarm on Silentbanker Trojan
 
 
 
Top Stories
Beyond ACORN: Cracking the infosec skills nut
[Blog post] Could the Government's cybercrime focus be a catalyst for change?
 
The iTnews Benchmark Awards
Meet the best of the best.
 
Telstra hands over copper, HFC in new $11bn NBN deal
Value of 2011 deal remains intact.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  38%
 
Your insurance company
  4%
 
A technology company (Google, Facebook et al)
  8%
 
Your telco, ISP or utility
  8%
 
A retailer (Coles, Woolworths et al)
  3%
 
A Federal Government agency (ATO, Centrelink etc)
  19%
 
An Australian law enforcement agency (AFP, ASIO et al)
  14%
 
A State Government agency (Health dept, etc)
  6%
TOTAL VOTES: 1886

Vote
Do you support the abolition of the Office of the Information Commissioner?