Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

New "Bugat" trojan harvesting banking credentials
SC Mag ^

Posted on 02/12/2010 12:10:30 PM PST by Gomez

Researchers have discovered a new banking trojan that is being used to steal the financial credentials of bank customers.

The "Bugat" trojan, discovered by SecureWorks researchers in January, has capabilities similar to the notorious data-stealing trojans Clampi and Zeus, according to Jason Milletary, security researcher with SecureWorks' Counter Threat Unit (CTU).

The malware monitors an infected user's web browsing activity and searches for the URLs of more than a dozen financial institutions, Milletary said. When a user accesses one of the targeted URLs, the trojan captures account credentials and sends them back to the criminal's remote server.

Milletary could not reveal which banks are currently being targeted, but said the trojan is updating its configuration data to include new financial institutions.

For certain targets, the trojan also conducts a phishing attack to extract additional information from a user that can be used for fraudulent transactions, Milletary said. The malware attempts to modify a bank's login page to include additional fields asking a user for information, such as their PIN number, date of birth or mother's maiden name.

In addition, the trojan can be used to steal Internet Explorer, Firefox and Flash cookies, browse and upload files from an infected computer, download and execute programs, upload a list of running processes, delete system files and render Windows unable to boot. 

The Bugat trojan is new and does not appear to be widespread, Milletary said. Currently, the trojan is being distributed by a Zeus botnet.

“We happened to observe one version of the Zeus botnet sending out instructions to infected machines to download and execute this trojan,” Milletary said.

Whoever is behind the trojan is probably testing it out to see how effective it is, he added.

The introduction of this tool demonstrates that there is a demand on the criminal market for malware designed for financial theft, Milletary said. “This might be a low-cost alternative, or one that's not as well-known as Zeus,” Milletary said.

The Bugat trojan has some capabilities not commonly found in other banking trojans, he added. For example, it uses HTTPS to secure its command-and-control communications to keep stolen data safe from other hackers. Also, it has the functionality to steal FTP credentials.


TOPICS: Computers/Internet
KEYWORDS: microsofttax

1 posted on 02/12/2010 12:10:31 PM PST by Gomez
[ Post Reply | Private Reply | View Replies]

To: ShadowAce

ping


2 posted on 02/12/2010 12:11:02 PM PST by Gomez (killer of threads)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Gomez

That’s why I only use my Linux laptop to do my online banking.


3 posted on 02/12/2010 12:12:16 PM PST by dfwgator
[ Post Reply | Private Reply | To 1 | View Replies]

To: Gomez

One more thing to worry about.


4 posted on 02/12/2010 12:22:56 PM PST by afraidfortherepublic
[ Post Reply | Private Reply | To 1 | View Replies]

To: Gomez

Isn’t there a browser that works on Windows that is safe anymore? I am tempted to go to Linux as well.


5 posted on 02/12/2010 12:25:10 PM PST by WakeUpAndVote (O)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dfwgator

That’s why I don’t do online banking and only use prepaid credit cards with small balances to buy online.


6 posted on 02/12/2010 12:25:55 PM PST by DannyTN
[ Post Reply | Private Reply | To 3 | View Replies]

To: rdb3; Calvinist_Dark_Lord; GodGunsandGuts; CyberCowboy777; Salo; Bobsat; JosephW; ...

7 posted on 02/12/2010 12:26:49 PM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: WakeUpAndVote

I like Linux Mint, it’s a very good GUI, it’s built on top of Ubuntu, but with a better user interface IMHO. It’s better if you are used to Windows XP.


8 posted on 02/12/2010 12:27:41 PM PST by dfwgator
[ Post Reply | Private Reply | To 5 | View Replies]

To: dfwgator

Tried them both. Pretty much useless unless you want to use it only for online banking or simple tasks(so far). Most software is pretty much not tuned into Linux yet. It’s really not worth the aggravation IMO.


9 posted on 02/12/2010 12:32:22 PM PST by foolishboi
[ Post Reply | Private Reply | To 8 | View Replies]

To: foolishboi

YMMV, but I’ve gotten wireless printing and network sharing working. But I will say, you can’t be afraid of going in and messing with some files to get some things working. But Linux has gotten better in that area over time.


10 posted on 02/12/2010 12:35:10 PM PST by dfwgator
[ Post Reply | Private Reply | To 9 | View Replies]

To: dfwgator

Yes it has gotten better. I thought I’d give it another shot after first trying it maybe five years ago. I was totally impressed when Mint picked up my wireless without any persuasion. I love to tinker but there’s a limit lol.


11 posted on 02/12/2010 12:40:20 PM PST by foolishboi
[ Post Reply | Private Reply | To 10 | View Replies]

To: WakeUpAndVote; dfwgator
I am tempted to go to Linux as well.

Ditto what dfw said. Ubuntu or Linux Mint are solid alternatives to WinDoze. Especially if you're using the computer to primarily surf the web, do online banking, send e-mails, etc.

Not so much if you're a big Gamer or do a lot of high-end movie-editing on your PC.

12 posted on 02/12/2010 1:17:09 PM PST by martin_fierro (< |:)~)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Gomez

Bookmark


13 posted on 02/14/2010 11:27:59 AM PST by DocRock (All they that TAKE the sword shall perish with the sword. Matthew 26:52 Gun grabbers beware.)
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson