Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

June 6th, 2011, 11:10 GMT · By

Banking Malware Hosted on Amazon's Cloud

SHARE:

Adjust text size:


Amazon slow to remove malware from its cloud platform
Enlarge picture
Security researchers from Kaspersky Lab have discovered a piece of Brazilian banking malware hosted on Amazon Web Services (AWS) and the cloud provider failed to respond in a timely manner.

The malware installer was distributed from an account on Amazon's Simple Storage Service (Amazon S3) as a .scr (screen saver) file.

Once executed, it installs a rootkit which prevents several security products from running, including avast! Antivirus 5, AVG Antivirus, ESET NOD32 and Avira AntiVir.

It also disables a browser security add-on called GBPlugin which is commonly distributed by Brazilian banks to their customers.

The malware is designed to steal financial information from nine Brazilian banks and two international ones, login credentials for Microsoft's Live Messenger and digital certificates used by eTokens.

In addition, it reports back with information about the infected computers, such as their name, CPU type and hard drive volume numbers.

"[...] This information is being used by some Latin American banks during login sessions to the banks in order to authenticate customers," explains Kaspersky Lab expert Dmitry Bestuzhev.

The malware siphons information via two methods: by sending it to a special Gmail address or by uploading it into a remote web database.

Brazilian banking malware has been increasing in sophistication during recent months. Just last month one such threat was found bundling a rootkit that is capable of infecting 64-bit Windows systems.

Cyber criminals commonly abuse web hosting services, normally free ones, and their ability to respond quickly is critical to the number of potential victims. Unfortunately, it seems that Amazon did not give this incident a high enough priority, because, according to Mr. Bestuzhev, the infector was still live twelve hours after the company was notified.

This is not the first time that AWS is abused by cyber criminals. In late 2009, security researchers found a ZeuS command and control server hosted on the platform. In both cases, attackers most likely used stolen credentials instead of paying for the service themselves.

TELL US WHAT YOU THINK:

1,423 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Researcher to Release WPA Cracking Tool for Amazon's Cloud

Amazon's New Cluster GPU Instances Used to Crack Passwords

Zeus Botnet Infiltrates Amazon's Cloud

Amazon EC2 Used for Hosting BitTorrent Clients

Amazon EC2 Spreads Malware

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM