IT Safety News - Your source for network security news, opinion, product comparisons and reviews. Virus, Worms, Antivirus and Security Information.
Showing posts with label financial malware. Show all posts
Showing posts with label financial malware. Show all posts
Wednesday, May 22, 2013
A new variant of the Citadel Trojan hunts on Payza users
The new version of financial malware Citadel aimed at users of the payment system Payza, said in an IT company Trusteer. According to experts, the malware starts a local vnutribrauzernuyu attack to steal financial details of users.
Recall that the Citadel - this Trojan is designed mainly to steal details of online banking, but it is also associated with the program-extortionist Reveton, which locks the computer and displays a warning about the need to transfer certain payments to unlock. Like most of the other Trojans, Citadel is embedded in the system processes an Internet browser, and can modify the page that you open on your computer. This technique is referred to as slang experts as MitB or Man in the Browser. It is quite difficult to detect by the user without the use of anti-virus solutions, as in the address bar of the browser issued a legal address of the visited site.
Friday, April 19, 2013
New version of Gozi financial malware placed in the MBR
Researchers from the IT company Trusteer discovered a new variant of the banking Trojan Gozi, capable of infecting the master boot record MBR, to avoid detection by antivirus software.
Recall that the MBR is the starting sector of the hard disk that contains the data on the partition of the support sections and information about the installed operating systems. Loading data from the MBR starts before the operating system is loaded with anti-virus software. That's why some sophisticated malicious programs are created based on the work of the MBR. Earlier work from the MBR used such malware as TDL4 or TDSS.
That is why in the operating system Windows 8 Secure Boot feature appeared to protect against zero-sector third-party records. Experts say the malicious placed in an MBR, it is very difficult to find and not all operating systems are in principle capable to handle MBR regular means.
Subscribe to:
Posts (Atom)
