Password screen
The SilentBanker Trojan is proficient at overcoming two-factor authentication
R E L A T E D   C O N T E N T
ADVERTISEMENT

SilentBanker Trojan enters stealth mode

Malware gets a rootkit

Iain Thomson in San Francisco, vnunet.com 08 Oct 2008
ADVERTISEMENT

Security analysts are warning of an improvement in the SilentBanker Trojan that makes it harder to detect and more effective at stealing data.

SilentBanker specifically targets financial web pages and tries to steal log-in details using a key-logger. Although it has been around since last year the new version has a rootkit that makes finding infected files very difficult.

"Whenever a user tries to view any files on the computer, the Trojan intercepts that request and removes any reference to the Trojan's files, making the files invisible," said Symantec researcher Liam O'Murchu.

"The last version of SilentBanker targeted over 400 banks, some of which use two-factor authentication.

"The current version, as well as hiding itself, has added extra protection to its configuration files in order to make it more difficult to discover which sites are being targeted."

When a user tries to search in the registry for files that indicate an infection, the rootkit in the Trojan intercepts the search request and automatically hides its files from view.

SilentBanker is causing major concern because it is especially good at defeating two-factor authentication. This involves the user having a separate log-in token that is synchronised with the bank's server to augment a password.

The Trojan subverts the two-factor transaction by intercepting communications before they are encrypted and forwarding them to the attacker, essentially making the security of two-factor authentication useless.

The software is being spread via spam and may prove very costly given the current wave of phishing attacks being propagated in the light of the recent world banking crisis.

See also:

ISSE 2008Integrated technologies the way forward, says McAfee  07 Oct 2008
SpamMalware-laden messages on the increase  07 Oct 2008
YouTubeTrojan attack promises adult clip  02 Oct 2008
VirusMalware responsible for 60 per cent of all attacks during the month  01 Oct 2008
Identity theftSecurity legislation heads to president's desk  20 Sep 2008

All Hacking
Tags: Threats-and-risks, Crime, Security-technology, Symantec, Trojan, Malware, Security, Software

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
C# Web Developer, Finance, London Financial Services Required: C#, ASP.NET, AJAX Fantastic opportunity not to be missed!! This is a great opportunity to work on a unique objectives that no other company is doing working ... more >
| JAM Recruitment
Senior Hardware Engineer Scotland/Edinburgh Communication Systems Permanent Position 40-45K+Benefits A leading organisation involved with the design and development of data acquisition systems and synthesis boards for a range of radar, signal intelligence and software radio ... more >
| JAM Recruitment
FPGA Engineer Defence/Safety Critical Buckinghamshire Permanent Position 45K+Benefits A leading UK defence organisation requires an experienced digital design engineer to strengthen its existing development team due to a number of long-term projects that have recently ... more >
| JAM Recruitment
DSP Engineer 3 Months Contract Hertfordshire £Excellent Rates£ This position requires you to have experience of measurement algorithms development for the generation and analysis of digital wireless communication standards including GSM, EDGE, UMTS, WLAN and ... more >
More job opportunities