Feeds

SpyEye mobile banking Trojan uses same tactics as ZeuS

Give us your number, mate, we'll send you a 'digital certificate' ...

Providing a secure and efficient Helpdesk

Cybercrooks have deployed a sophisticated man-in-the-mobile attack using the SpyEye banking Trojan toolkit.

The Trojan, which infects Windows machines, displays additional content on a targeted European bank's webpage that requests prospective marks to input their mobile phone number and the IMEI of the device. The bank customer is informed the information is needed so that a new "digital certificate" can be sent to the phone.

The so-called certificate contains the malicious executable (sms.exe) that infects Symbian-based smartphones along with another executable (SmsControl.exe) that displays a message designed to hoodwink users into believing that the only thing delivered was a digital certificate. Net security firm F-Secure detects this malware as Spitmo-A.

The European bank targeted in the attack uses SMS-based mTANs to authorise transfers. Details of how the SMS-based mTANs are delivered to the attacker are still under investigation, but preliminary research suggests that they are delivered via HTTP, and not via SMS as with an otherwise similar earlier attack that used the infamous ZeuS cybercrime toolkit.

The earlier ZeuS-based attack also used a file called SmsControl.exe as part of its payload. Presenting a Trojan as a digital certificate, one of the tricks up the sleeve of the SpyEye-based attack, also appeared in the earlier ZeuSMitmo attack. Despite these similarities, and the rumoured merger between ZeuS and SpyEye – the two biggest toolkits for banking Trojan creation – the two strains of malware are otherwise dissimilar, F-Secure reports.

More information on the SpyEye-based mobile banking Trojan attack can be found in a blog post by F-Secure here. ®

Choosing a cloud hosting partner with confidence

More from The Register

next story
Same old iPad? NO. The new 'soft SIMs' are BIG NEWS
AppleSIM 'ware to allow quick switch of carriers
Arab States make play for greater government control of the internet
Nerds told to get lost in last-minute power grab bid at UN meeting
Brits: Google, can you scrape 60k pages from web, pleeease
Hey, c'mon Choc Factory, it's our 'right to be forgotten'
Of COURSE Stephen Elop's to blame for Nokia woes, says author
'Google did have some unique propositions for Nokia'
It's even GRIMMER up North after MEGA SKY BROADBAND OUTAGE
By 'eck! Eccles cake production thrown into jeopardy
Mobile coverage on trains really is pants
You thought it was just *insert your provider here*, but now we have numbers
Don't mess with Texas ('cos it's getting Google Fiber and you're not)
A bit late, but company says 1Gbps Austin network almost ready to compete with AT&T
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.