NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Security / Spyware Threats

Spyware Threats


Trojan Advertised as Open Source Antivirus Solution

Hijacks online banking sessions on infected computers

By Lucian Constantin, Web News Editor

11th of June 2009, 12:15 GMT

Adjust text size:


Virus Doctor e-mails distribute banking information stealing trojan
Enlarge picture
Security researchers from antivirus vendor Bitdefender warn of a new malware-distribution campaign that attempts to pass a computer trojan as open source antivirus software. Once installed on the computer, the malware directs browser requests to Paypal, Abbey and Halifax to phishing pages.

E-banking customers should avoid e-mails offering free downloads of an alleged open source antivirus program called Virus Doctor. "This Software has being Review and Accepted as Open Source Software with the Aid to provide full Support for all your online Security," the poorly written e-mail messages read.

Clicking on the included link to download a file named setup.exe is not a good idea, as it will actually serve a trojan installer, in the form of a self-extracting archive. "Its purpose is to replace the content of C:\WINDOWS\System32\drivers\etc and to alter the Web browser's behavior, by automatically loading maliciously crafted pages for phishing purposes of PayPal, Abbey and Halifax," the Bitdefender researchers explain.

When a user attempts to access the websites of these institutions from a computer infected with this malware, their browsing session is hijacked and they are redirected to domains registered in China and Korea. The fake pages ask users to input sensitive financial and personal details such as full name, address, credit card number, along with expiration date, CVV2 code and PIN.

If submitted, all the information is stored on servers under the control of the cybercriminals behind this scheme. One interesting aspect of the fake websites is that all the links in the menus are directing to the legit pages on the original Paypal, Abbey, or Halifax websites.

Another computer trojan that attempts to steal financial information by changing the normal browser behavior is Torpig. Launched in 2006, the Torpig trojan is said to have compromised some half a million banking details to date. This trojan watches for a list of e-banking websites and, if any of them is opened in the browser, it injects a rogue form asking users for sensitive information.

Given the success of Torpig, which, some could argue, employs less deceptive social engineering techniques than this latest threat, users should exercise extra caution. Use trusted sources, such as Softpedia, to download software instead of trusting links spammed through e-mails.

TAGS:

Virus Doctor | malware distribution | session hijacking | browser redirect | Bitdefender
Read by 1,827 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
NOT RATED 0 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Researchers Peak Inside the Torpig Trojan Infrastructure

Three Year Old Trojan Compromised Half Million Banking Details

Australian Phishing Operation Leaks Stolen Data

Your Delivery Failed – Have This Trojan Instead

Banking Trojan Distributed Through Fake UPS E-mails

Browser Vulnerability Opens Door to New Phishing Techniques

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM