SecureWorks finds stolen data cache, variants of Prg trojan

Powered by SC Magazine
 

Researchers at SecureWorks have discovered several caches of stolen data containing the personal and financial information of 10,000 corporate and home PC users, as well as new variants of the Prg trojan.

The caches contain bank and credit union, credit card and Social Security numbers, usernames and passwords, according to SecureWorks officials.

Researcher Don Jackson said that hackers are working around encryption standards.

"When data is located, it is always encrypted to keep others from ‘leeching.’ New variants of the trojan have new ways of encrypting that data, making old analysis tools obsolete," said Jackson. "New encryption methods must be reverse-engineered from raw machine code."

The company said that the trojan’s variants have the ability to lift sensitive data from PCs before that data is encrypted and sent to SSL-protected sites. Numerous hacker groups have launched attacks using the malware, according to SecureWorks.

Jackson told SCMagazine.com today that the trojan highlights the trend of increased use of malware-creation kits.

Earlier this month, trojans controlled by Russian gangs attacked mostly Italian victims in a large-scale operation aided by the MPACK kit.

"It’s being posted on hacker sites in the underground, and people just buy it and use it," he said, adding that the kits "allow people to send out these variants pretty quickly."

SecureWorks finds stolen data cache, variants of Prg trojan
 
 
 
Top Stories
The True Cost of BYOD - 2014 survey
Twelve months on from our first study, is BYOD a better proposition?
 
ANZ looks to life beyond the transaction
If digital disruptors think an online payments startup could rock the big four, they’ve missed the point of why people use banks, says Patrick Maes.
 
What InfoSec can learn from the insurance industry
[Blog post] Another way data breach laws could help manage risk.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
What is delaying adoption of public cloud in your organisation?







   |   View results
Lock-in concerns
  29%
 
Application integration concerns
  3%
 
Security and compliance concerns
  27%
 
Unreliable network infrastructure
  9%
 
Data sovereignty concerns
  21%
 
Lack of stakeholder support
  3%
 
Protecting on-premise IT jobs
  4%
 
Difficulty transitioning CapEx budget into OpEx
  3%
TOTAL VOTES: 1051

Vote