Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

February 9th, 2011, 18:09 GMT · By

RSA Researchers Confirm ZeuS Code and Features in SpyEye

SHARE:

Adjust text size:


SpyEye imports HTML injection mechanism from ZeuS
Enlarge picture
Security researchers from RSA have confirmed that the SpyEye author is working on a "super trojan" by merging features from ZeuS into his own creation, sometimes by copying entire chunks of code.

When rumors first appeared last year that SpyEye and ZeuS will be merged together, after Slavik gave his source code to Harderman, aka Gribodemon, the security researchers were skeptical.

This is because at the time SpyEye was ZeuS' biggest competitor on the underground market and even featured a "kill ZeuS" option.

However, starting with version 1.3 development builds, the malware began to show signs that the rumors were true and ZeuS features were slowly being ported to SpyEye.

The most important addition from ZeuS so far is the HTML injection engine for Internet Explorer, which is a core component in such banking trojans.

Harderman acknowledged that ZeuS's mechanism was practically copied it in its entirety without any major modifications.

According to the RSA researchers, the main reason why ZeuS' injection component was better is its handling of cached pages.

The old SpyEye mechanism was only capable of injecting code into HTML pages are they were being downloaded from the Internet, however, on repeated visits, the browser loads the page from its cache.

Because of this, SpyEye deleted the cache after every injection to make sure that the page is always downloaded from the server. Meanwhile, ZeuS is capable of injecting rogue code in cached pages, making its mechanism more reliable.

Other features sported by the SpyEye 1.3 version include a new encryption method for the configuration file, an encapsulated executable modular architecture, PE resources and remote process injection.

"RSA believes that the Zeus Trojan may gradually become a relic of the past. Although the old Zeus may still be the subject of new underground upgrades, it will most likely begin fading away as fraudsters turn to SpyEye – a Trojan code offering both technical support and future upgrades," the researchers write.

TELL US WHAT YOU THINK:

1,635 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


ZeuS Development Might Continue as Source Code Offered for Sale

Most Computers Infected with SpyEye Are Located in Poland

First Toolkit Resulting from ZeuS-SpyEye Merger Hits the Underground Market

ZeuS Builder Service Spotted on the Underground Market

SpyEye Features Being Ported to ZeuS

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM