New threat set to dethrone Zeus

Voted by

BrianH2October 11th, 2010

The position of the infamous Zeus trojan may be usurped by a new upstart that is unknown to four of the six largest antivirus companies and has already been used by a criminal group to empty bank accounts across Europe and America.

Zeus

(Credit: Microsoft)

The latest incarnation of the Carberp trojan possesses most of the tricks used by Zeus to steal millions of dollars from bank accounts around the world, and targets the most popular operating systems and web browsers including Microsoft's Windows 7, Vista and XP, as well as the Internet Explorer and Mozilla Firefox web browsers.

It also attempts to seek and destroy or disable rival bank account-stealing trojans, including Zeus. However, it is not known if the malware possesses the capability to remove the malware.

Security companies have yet to agree on the characteristics of Carberp. To some security companies Carberp is considered a derivative of Zeus. Less harmful variants of Carberp exist including malware downloaders and generic trojans, but this latest instance is considered the first fully-capable banking trojan of its kind.

"Carberp is different. It is very, very sophisticated and I expect the infection rates to be the same as Zeus," said Andreas Baumhof, co-founder and chief technology officer of secure banking authentication firm TrustDefender. He said the trojan is as yet unknown to the big antivirus companies.

"However, Zeus has a much bigger distribution network which is why Carberp is under the radar and used only in targeted attacks."

Infection could spread quickly to other nations with a small modification to the trojan's configuration file, Baumhof said.

The company's research arm identified the new Carberp variant three months ago and has now deconstructed it.

Technicians report that Carberp can hijack the two-factor authentication used by some of the most popular banks by borrowing the capabilities of rival trojans Zeus, Gozi and Spyeye to inject HTML overlays.

It can also install onto PCs without the need for administration rights, meaning it can bypass the tougher access controls of Microsoft's latest operating systems, and has a sophisticated and rarely-seen browser-hijacking capability that can commandeer all internet traffic, including secure HTTPS with Extended Validation-SSL.

From the labs

Carberp can install on a machine without the need for administrative access, but will only infect the current logged-in user and does not infect the kernel, according to the security company.

"The creators don't care if Carberp is removed after a couple of days, because by then, they have done what they need to do," Baumhof said.

He said Carberp lacks the full functionality of Zeus, but it has the same "high-level of sophistication".

The TrustDefender report states that Carberp:

  • Will not make any changes to the registry (only in memory modifications)
  • Transmits stolen data in real time to a command and control (C&C) server
  • Will automatically make a few requests to download additional files. The first request will transmit a unique ID of the computer to the C&C server (POST /set/task.html with id). It will then request an upload of all running processes, including a POST request to /set/first.html, and will then immediately download three files.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

Tech Blueprint

ZDNet Australia Live

http://t.co/aDIOqQ4c http://t.co/NeUOcLt5

What has the debt level got to do with what plan people chose? I'd point out that the debt wont be $50 billion but i'd be wasting my bre...

9 minutes ago by mstat_z on NBN users opt for 100Mbps

Quigley is entirely politically motivated, this is headline grabbing and nothing more. The statistic should read - "of those who took up ...

29 minutes ago by merarischroeder on NBN users opt for 100Mbps

RT @zdnetaustralia: NSW outs datacentre deal details: http://t.co/A1Cj4Eot ^LH

"the artificial speed tiers will mean that on average speeds the country will be left well behind others and social inequality will incre...

41 minutes ago by Hubert Cumberdale on NBN users opt for 100Mbps

The most insulting aspect of the ads is CommBank's expectation that we would accept a bank account with fees unless you deposit $2000/mth...

52 minutes ago by gikku on Triple J's Spotify conundrum

NBN users opt for 100Mbps - Communications - News http://t.co/3A84AASP

That's right. Quigley DOES know best. So when Quigley presents a plan to the shareholders (us) and says "this is our worst case scenario...

1 hour ago by Hubert Cumberdale on NBN users opt for 100Mbps

"NBNCo predict 13% of premises passed by fibre will opt for wireless because it is cheaper." Which leaves 87% well above the 70% estimate...

1 hour ago by Beta on NBN users opt for 100Mbps

HC the critics said the NBN wouldn't make a cent (yes, yes here comes the, it's still in debt arguments - we know what you meant and so d...

1 hour ago by Beta on NBN users opt for 100Mbps

Look what you did Gwyn...LOL. Yes, but as you have been told umpteen times Mathew (whenever you sprout the same old repetitive lines abo...

1 hour ago by Beta on NBN users opt for 100Mbps

It's great that in one area NBNCo are beating the prediction on speed tiers in the Corporate Plan (page 118). Unfortunately it is the onl...

1 hour ago by mathew42 on NBN users opt for 100Mbps

10 cool iPad apps you'll wish you found sooner | 2 of 10 http://t.co/M9SXbnJS via @zite

Do you have a reference for the 40% in Willunga? The only public figures I've seen are 29% for Willunga and 26% for Kiama. It would cert...

1 hour ago by mathew42 on NBN users opt for 100Mbps

Considering that Quigley wrote the corporate plan based on a number of studies one would expect him and the plan to know best.

1 hour ago by mathew42 on NBN users opt for 100Mbps

yep don't worry, I'm sure the anti-NBN zealots will find some other ridiculous line to fill the void. I imagine it'll be "oh but these ar...

1 hour ago by Hubert Cumberdale on NBN users opt for 100Mbps

SA Health's journey to ehealth Business News ZDNet Australia: Implementing e-health services for an entire state... http://t.co/QuiOy7OQ

London to become Intel's city-living R&D testbed - ZDNet UK (blog): IT PROLondon to become Intel's city-living R... http://t.co/5qdivDa1

You would think so, but after this post went live Turnbull's office finally got back to me and said that, if they win office next year, t...

1 hour ago by braue on NBN cost-benefit analyses are so 2011

Carriage dialect poke is a vastly predominant brand in a completely logical price. Honourableness quality of products of the modern coach...

2 hours ago by Teleuplique on Appeal to save wiki-linked Twitter accounts

#Google #Australia Much ado about Google's tax http://t.co/DCMsJGyN

You don't appear to understand what the CVC charge is. The CVC is a charge that the ISP pays and is waived while there's too few people c...

2 hours ago by OxleyDave on NBN users opt for 100Mbps

RT @zdnetaustralia: NSW outs datacentre deal details: http://t.co/A1Cj4Eot ^LH

by http://t.co/vmlLt4bh: Build your own smartphone stand: Looking for a smartphone stand, but not interested in d... http://t.co/DptVvkoB

Well, indeed Beta; indeed! Of course, the response to actual favourable data about the NBN is the same everywhere - out come the concern...

2 hours ago by Gwyntaglaw on NBN users opt for 100Mbps

Build your own smartphone stand: Looking for a smartphone stand, but not interested in dishing out the dough? We... http://t.co/TgSeZIdM

last couple of hours to submit your application for #crmidol. Step up and take your chance! http://t.co/7vQxdbY3 #scrm #crm #value

But, but, but... they could do that on dial-up ;-)

2 hours ago by Beta on NBN's Tassie upgrade to cost $1.3 million

The rural Silicon Valley http://t.co/vqV6bl5i

RT @JamesVickery: NBN users opt for 100Mbps http://t.co/atP8fi1L

Build your own smartphone stand http://t.co/IY6VxA7n

RT @zdnetaustralia: NSW outs datacentre deal details: http://t.co/A1Cj4Eot ^LH

You don't need Mathew Gwyn, you have the other usual suspects rolling in with their FUD, like clockwork. Of course these two perpetually...

3 hours ago by Beta on NBN users opt for 100Mbps

Another way of saying that is "of the 3,500-11,000 [votes], they won't be representative of the approximately 10 million... households". ...

3 hours ago by Gwyntaglaw on NBN users opt for 100Mbps

The rural Silicon Valley http://t.co/jhEFQwSX

JobWatch: where the ICT jobs are http://t.co/e6gQvhxz via @zdnetaustralia #ICT #recruitment

The rural Silicon Valley: What happened in Senate Estimates this week? What's the issue with tech company taxes?... http://t.co/Umoa7CHX

Sweet: "Customers are picking the top fibre plan that is available on the #NBN more than any other plan" http://t.co/yUFHdYFc

RT @CorrieB: An iPad for every child: Inevitable or impossible? http://t.co/I7uS8l9s Thx to @timbuckteeth for this; http://t.co/jxkqIRIp

Interesting tech analysis podcast re: phone cloning and Craig Thomson from zdnet http://t.co/p8jlCvvG

@zdnetaustralia Thoughtful piece to end the week on. Thanks @joshgnosis

Triple J's Spotify conundrum http://t.co/iy1e2DRp via @zdnetaustralia

RT @zdnetaustralia: NSW outs datacentre deal details: http://t.co/A1Cj4Eot ^LH

BYOD for iOS devices is not a big deal, provided a passcode is enforced and jailbroken devices are excluded. But if Google can sort out ...

3 hours ago by umbria on BYOD too immature for us: Human Services

Triple J not bound to advertising rules like its broadcast. No diff to ABC online or magazines though... http://t.co/JPUr7Fv4

Triple J's Spotify conundrum: Has Triple J managed to find the balance between meeting editorial policy and keep... http://t.co/8UYsHZ6D

RT @joshgnosis: Listening to Triple J on Spotify has ads for Commonwealth Bank. But that's okay apparently. http://t.co/O7zmcpvT

Listening to Triple J on Spotify has ads for Commonwealth Bank. But that's okay apparently. http://t.co/O7zmcpvT

How does Triple J find the balance with meeting editorial policy and keeping up with the latest technology? http://t.co/qdWgybfm ^jt

RT @zdnetaustralia: NSW outs datacentre deal details: http://t.co/A1Cj4Eot ^LH

NBN users opt for 100Mbps http://t.co/ftKGRzye

#IT Priorities: #servers and #storage: webinar sponsored by @IBM http://t.co/BGq8LYd5 via @zdnetaustralia

Post 'social' improved speed to information and context: By Oliver Marks | May 24, 2012, 9:47pm PDT... http://t.co/VGN2hxtp #socialmedia

RT @zdnetaustralia: Should bug hunting for biometric systems be restricted to govt and industry? http://t.co/oj0oOkv7 ^ML

Exploring: http://t.co/WzikDISk

This story has been voted 12000 times in the last 24 hours!

1 day ago, Is Bill Gates a great leader?

This story has been voted 10 times in the last 24 hours!

2 days ago, CeBIT 2012 opens: photos

This story has been voted 15 times in the last 24 hours!

2 days ago, Lenovo ThinkPad 3G tablet (32GB)

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar