Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security

October 13th, 2010, 10:46 GMT · By

Microsoft Takes On the World's Leading Banking Trojan

SHARE:

Adjust text size:

ZBot detection added to new MSRT version
Enlarge picture
Microsoft has added detection routines for the infamous ZeuS trojan to the new Malicious Software Removal Tool (MSRT) version, delivered via Windows Update yesterday.

ZeuS is one of the most prevalent computer trojans and it is commonly used by cyberfraudsters, due to its flexibility and sophisticated information stealing features.

ZeuS is sold as a crimeware toolkit, which criminals can buy and use to generate customized versions of the trojan and associated command and control (C&C) server.

To differentiate between the toolkit and the actual trojan, some security researchers and antivirus vendors refer to the first as ZeuS and the latter as ZBot (short for ZeuS Bot).

ZBot-infected computers join together to form remotely controlled botnets, and because numerous variations of the trojan are released on a daily basis, there are hundreds of active ZeuS botnets at any given time.

ZBot entry in MSRT's list of detected malware
Enlarge picture
"This family is quite prolific even if the intent behind some of the botnets is unclear. That said, we find ourselves knocking on Zbot’s door this month, and we’re glad we are," says Matt McCormack from Microsoft's Malware Protection Center (MMPC) in Melbourne, Australia.

"Zbot is the latest addition to MSRT’s ever-growing list of malware, and we hope to continue protecting the Windows ecosystem with this new family firmly in our sights," he adds.

The widespread aspect of this trojan family, in both number of victims and active versions, makes it hard for antivirus vendors to keep up with the threat.

In addition, many ZeuS gangs take a hit-and-run approach to cyberfraud. They start out by making sure their Zbot variant is not detected by any of the top AV products and then launch email or Web-based attacks to distribute it.

Once deployed, the trojan monitors browsing sessions and captures online banking credentials, credit card details and other financial or sensitive information. This stolen data is immediately abused.

Chances are that by the time AV vendors add detection for a particular variant, criminals have already achieved their purpose and siphoned tens of thousands of dollars from the compromised bank accounts.

Just recently, authorities in US, UK and Ukraine, collaborated to dismantle an international ZeuS criminal network responsible for losses of more than $70 million.



1,270 hits
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


New ZeuS Variant Uses File Infector to Prolong its Life

Money Mule-Assisted Fraud Continues Despite Recent Arrests

Five Key ZeuS Fraud Suspects Arrested in Ukraine

Authorities Charge 37 Alleged Money Mules in New York

UK ZBot Fraudsters Officially Named and Charged

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM