Feeds

SpyEye mobile banking Trojan uses same tactics as ZeuS

Give us your number, mate, we'll send you a 'digital certificate' ...

Providing a secure and efficient Helpdesk

Cybercrooks have deployed a sophisticated man-in-the-mobile attack using the SpyEye banking Trojan toolkit.

The Trojan, which infects Windows machines, displays additional content on a targeted European bank's webpage that requests prospective marks to input their mobile phone number and the IMEI of the device. The bank customer is informed the information is needed so that a new "digital certificate" can be sent to the phone.

The so-called certificate contains the malicious executable (sms.exe) that infects Symbian-based smartphones along with another executable (SmsControl.exe) that displays a message designed to hoodwink users into believing that the only thing delivered was a digital certificate. Net security firm F-Secure detects this malware as Spitmo-A.

The European bank targeted in the attack uses SMS-based mTANs to authorise transfers. Details of how the SMS-based mTANs are delivered to the attacker are still under investigation, but preliminary research suggests that they are delivered via HTTP, and not via SMS as with an otherwise similar earlier attack that used the infamous ZeuS cybercrime toolkit.

The earlier ZeuS-based attack also used a file called SmsControl.exe as part of its payload. Presenting a Trojan as a digital certificate, one of the tricks up the sleeve of the SpyEye-based attack, also appeared in the earlier ZeuSMitmo attack. Despite these similarities, and the rumoured merger between ZeuS and SpyEye – the two biggest toolkits for banking Trojan creation – the two strains of malware are otherwise dissimilar, F-Secure reports.

More information on the SpyEye-based mobile banking Trojan attack can be found in a blog post by F-Secure here. ®

Protecting against web application threats using SSL

More from The Register

next story
Brit telcos warn Scots that voting Yes could lead to HEFTY bills
BT and Co: Independence vote likely to mean 'increased costs'
Phones 4u slips into administration after EE cuts ties with Brit mobe retailer
More than 5,500 jobs could be axed if rescue mission fails
New 'Cosmos' browser surfs the net by TXT alone
No data plan? No WiFi? No worries ... except sluggish download speed
Radio hams can encrypt, in emergencies, says Ofcom
Consultation promises new spectrum and hints at relaxed licence conditions
Blockbuster book lays out the first 20 years of the Smartphone Wars
Symbian's David Wood bares all. Not for the faint hearted
Bonking with Apple has POUNDED mobe operators' wallets
... into submission. Weve squeals, ditches payment plans
This flashlight app requires: Your contacts list, identity, access to your camera...
Who us, dodgy? Vast majority of mobile apps fail privacy test
Apple Watch will CONQUER smartwatch world – analysts
After Applelocalypse, other wristputers will get stuck in
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
Security and trust: The backbone of doing business over the internet
Explores the current state of website security and the contributions Symantec is making to help organizations protect critical data and build trust with customers.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.