The Inquirer-Home

Zeus banking Trojan is hitting Firefox

Not just Microsoft
Wed Apr 21 2010, 14:34

REPORTS HAVE SURFACED that Internet Explorer users are not the only targets of the Zeus banking Trojan - Firefox users are now also under threat.

Security vendor Trusteer said that Zeus 1.6 was in the wild, while a beta version called version 2 of it was being tested with certain criminal groups that had access to the earlier versions. The main difference between these and the prior versions is that they target the Firefox browser as well. Trusteer said it is being found on one of every 3,000 computers it monitors.

Zeus, which has been around since late 2005, has been used by criminal organisations to commit targeted attacks against bank customers. It does this by keystroke logging and spreads through drive-by downloads or phishing attacks.

Older Zeus versions have usually been sold on the black market bundled with services. The Zeus botnet with an admin panel, web injection scripts and an exploit system could be bought for around $400. From the six months to March, security vendor Trend Micro blocked nine million attempted Zeus-related attacks.

Previously the Trojan couldn't attack Firefox, but Trusteer said that version 1.6 supports 'HTML injection' and 'transaction tampering', which bypass strong authentication and signing protocols.

Apart from its new ability to use Firefox, Trend Micro security expert Rik Ferguson told The INQUIRER that the fact it is a new version is almost irrelevant when it comes to the detection of the Trojan with security software.

He said, "One of the things that happens with Zeus, which happens with all malware these days, is that it gets packed and re-packed and continually re-packed in order to avoid traditional signature-based anti-malware solutions."

There is also a new Jabber chat module in Zeus 1.6 that can relay banking credentials back to criminals in real-time, which is an attempt to overcome two-factor authentication. µ

Share this:

Comments
Relationship

Haha, 'related articles' underneath this article links "Wacom Bamboo Pen & Touch" (the review), as related.
I wonder how wacom feels about that one, is it really better to be mentioned negatively than not at all? Mythbusters should get into the depths of that myth.

posted by : W.-, 22 April 2010 Complain about this comment
Why don't

Why don't governments or banks send hit men after these theives?
I mean if you can buy things from them, they recive your info, then there is a way to track them.
I say burn them alive and post it on liveleak.

posted by : Mahhn, 21 April 2010 Complain about this comment
This is bogus

First off, there is no 1.6. It was a beta 1.4 that is going to be released as 2.0. Also, Zeus has been stealing information out of Firefox for a long time. With version 1.3 the webinjects file will now work with Firefox and it costs extra.

posted by : Kevin Stevens, 21 April 2010 Complain about this comment
Security, what security?

Six months ago FireBadger couldn't even spell 'insecure bloated browser'.

Now they are one.

posted by : Flightcrank, 21 April 2010 Complain about this comment
aboutus
Advertisement
Subscribe to INQ newsletters
Advertisement
INQ Poll

Authorities in several countries raided Megaupload recently, shut down all of its services, seized hundreds of servers and arrested several of its executives on criminal charges.

Do you think the move was justified?