Jericho botnet hits financial web sites

Powered by SC Magazine
 

Targets passwords and login credentials used at 100 financial institutions.

A new botnet has been detected that steals passwords and login credentials and has targeted more than 100 financial and banking domains.

The Jericho botnet was a variant of banking trojans like Jorik, according to Palo Alto Networks which discovered 42 samples of the malware.

Each unique but related botnet sample was delivered from Israeli IP space, but the engineering of the file appears to be of Romanian origin. The majority of URLs used to deliver the malware ended in ierihon.com (Ierihon means “Jericho” in Romanian).

The malware was  designed to avoid traditional signature-based anti-virus detection and could inject itself into the Windows logon to maintain persistence on the infected host after a reboot.

"What was a bit more interesting was just how efficient the malware was at injecting itself into valid applications such as Firefox, Chrome, Java, Outlook and Skype, and then repurpose their capabilities," the company said. "This not only enables the malware to hide within approved applications during run time, but it also means that standard methods for observing Windows API calls are subverted.”

The top anti-virus solutions detected 3.2 per cent of the 42 samples analysed, a number that increased to 39 per cent over a week.

This article originally appeared at scmagazineuk.com

Copyright © SC Magazine, UK edition


Jericho botnet hits financial web sites
 
 
 
Top Stories
Innovating in the sleepy super industry
There’s little incentive to be on the bleeding edge, so why is Andrew Todd fighting so hard?
 
How technology will unify Toll
The systems headache formed through 15 years of acquisitions.
 
Immigration breached Privacy Act with data leak
Pilgrim slams "copy and paste" of asylum seeker data.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  38%
 
Your insurance company
  3%
 
A technology company (Google, Facebook et al)
  7%
 
Your telco, ISP or utility
  8%
 
A retailer (Coles, Woolworths et al)
  2%
 
A Federal Government agency (ATO, Centrelink etc)
  20%
 
An Australian law enforcement agency (AFP, ASIO et al)
  15%
 
A State Government agency (Health dept, etc)
  5%
TOTAL VOTES: 844

Vote