Feeds

Entirely new trojan quietly wheeled into black hat forums

Pandemiya is 25,000 lines of original password-pinching botnet badassery

Top 5 reasons to deploy VMware with Tegile

An RSA researcher claims to have found an entirely new trojan during his trawls of the criminal underground.

RSA researcher Eli Marcus says the "Pandemiya" trojan comprises about 25,000 lines of fresh code. With most malware based on proven platforms, entirely new code is a rarity.

Pandemiya is nasty: it infects Windows PCs, steals data from forms, creates fake web pages and takes screen shots to send back to the botmasters who deploy it.

The software is modular and pervasive, and unique thanks to its ability to inject itself into all new processes via the Windows security registry function CreateProcess API.

It even has an upgrade path: Marcuswrites that a US$1,500 version offers basic functions but a US$2,000 cut allows .dll file plug-ins to enhance its functionality. A Facebook attack module is reportedly in the works.

"The advent of a freshly coded new trojan malware application is not too common in the underground," Marcus writes, adding that the modular approach means Pandemiya could become "more pervasive in the near future."

Pandemiya can also sign off botnet files, a trick Marcus said helped prevent hijacking and analysis by cops and security bods. Dynamic encrypted communications help it to dodge network analysers.

Like other trojans, Pandemiya is foisted on machines through exploit kits and drive-by infections that target vulnerabilities in buggy wares such as Java, Silverlight and Flash.

Marcus speculated the trojan was relatively unknown until now due to its high price and new-kid-on-the-block status compared to the likes of Zeus and Citadel.

The good news is that Pandemiya can be removed with a little registry-tweaking and command line action. ®

Top 5 reasons to deploy VMware with Tegile

More from The Register

next story
'Regin': The 'New Stuxnet' spook-grade SOFTWARE WEAPON described
'A degree of technical competence rarely seen'
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
You stupid BRICK! PCs running Avast AV can't handle Windows fixes
Fix issued, fingers pointed, forums in flames
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
prev story

Whitepapers

Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
How to determine if cloud backup is right for your servers
Two key factors, technical feasibility and TCO economics, that backup and IT operations managers should consider when assessing cloud backup.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Getting ahead of the compliance curve
Learn about new services that make it easy to discover and manage certificates across the enterprise and how to get ahead of the compliance curve.