Citadel variant won't be lost in translation

By

Includes HMTL injection scripts.

A new variant of the Citadel banking trojan has been found which has been cleverly tweaked to hasten the automated theft and sale of consumer data.

Citadel variant won't be lost in translation

The trojan was packaged with varying HTML injection scripts allowing fraudsters to display web pages in a specific language and trick users' into divulging financial or sensitive information about themselves.

Victims had seen fake web pages telling them that their Amazon account was blocked, for instance, and that they should enter their information to gain access again, Trusteer researchers said.

In reality, fraudsters had planted the malware with scripts delivering socially engineered ruses in English, Italian, Spanish, French or German.

This article originally appeared at scmagazineus.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

"VoidProxy" PhishKit targets Google and Microsoft users

"VoidProxy" PhishKit targets Google and Microsoft users

First npm worm "Shai-Hulud" released in supply chain attack

First npm worm "Shai-Hulud" released in supply chain attack

Apple adds "mercenary spyware" protection to new A19 chip

Apple adds "mercenary spyware" protection to new A19 chip

Phishing attack nets enormous npm supply chain compromise

Phishing attack nets enormous npm supply chain compromise

Log In

  |  Forgot your password?