New Commercialized Trojan Takes Fresh Approach To Password-Stealing


Userlevel 7
Badge +56
Unlike most banking malware of today, new Pandemiya skips the Zeus source code and starts from scratch.
Security researchers with RSA reported today that they found a new commercial Trojan malware program in the wild that is one of the first of its kind in a long while to not be based on source code from common variants of commercialized malware like Zeus or Carberp.
Called Pandemiya, the malware offers features and functionality similar to its predecessors, with one key difference in how it injects code and behaves on infected machines. Its authors have started marketing the Trojan for between $1,500 and $2,000, depending on the plug-in add-ons chosen by black-market customers.
"This one is very interesting because it is written and coded completely from scratch, which is very unusual in our field, because most of the banking Trojans today rely heavily on previously leaked source code," Uri Fleyder, cybercrime research lab manager for RSA Research, told Dark Reading.
According to the researchers at RSA, the new Pandemiya application was the product of a year of coding and contains more than 25,000 lines of original code in C. Where Pandemiya is most different from Zeus variants is in its injection technique.
"This malicious code writer has chosen to use quite a novel technique for injecting its malicious code into every new process in the victim's computer," Fleyder says. "This kind of code injection is not very common in this type of threat."
The software takes advantage of a Windows function that has the operating system forcing every process through the CreateProcess API and loading all of the DLLs under that registry key.
"This way, Pandemiya operates the injection mechanism of itself into every new process opened on the victim's computer post-installation," he says. "I think it is harder for the endpoint-based solutions or security protection solutions to block and detect this new threat, because it has a new behavior. So they need to make new signatures and new behavioral patterns, because it behaves a little bit differently than the usual Trojans, so it is harder for the endpoint solutions to detect it."
 
Full Article
 
Daniel

0 replies

Be the first to reply!

Reply