CoreBot Becomes Full-Fledged Banking Trojan

  • 11 September 2015
  • 1 reply
  • 133 views

Userlevel 7
Badge +54
See Also - Corebot is the new data Stealer discovered by IBm’s X-Force
 
By Eduard Kovacs on September 11, 2015 IBM reported in August that its researchers had come across CoreBot, a new piece of malware designed to steal data from infected devices. Initially, the threat only had limited capabilities, but IBM now says CoreBot has become a full-fledged banking Trojan.

The first CoreBot samples analyzed by IBM were designed to steal locally stored sensitive information, but they lacked the capability to intercept and steal data in real time. However, experts noted at the time that the malware used a modular plugin system that allowed its developers to easily add new capabilities. Full Article

1 reply

Userlevel 7
Badge +54
 by Chris Brook September 15, 2015
 
                                                   



Perhaps the malware’s most telling characteristic is a new list of 55 URL triggers – triggers that researchers at IBM’s Security Intelligence claim are tied to a handful of online banking sites in the U.S., Canada, and the U.K. and can launch webinjects.

When the firm first published research on CoreBot late last month, researchers noted the malware’s flexibility, acknowledging its modular design as something that could potentially allow for the easy addition of new mechanisms later down the line.
 
Full Article

Reply