Beware of New Identity Theft Gozi TrojanBest Security Tips offers daily news, information, advices and tips about spyware, adware, viruses, trojans, web vulnerabilities, hackers, other threats    | Register now | Login
   
TIPS NEWS TOOLS DOWNLOADS MALWARE FORUM BOOKS FREE MAGAZINES FREE WEBCASTS & VIDEOS
GFI LANguard Network Security Scanner - Dld 30-day trial! del.icio.us  digg  Furl  NewsVine  Spurl  Blinklist  Ma.gnolia  Reddit  Tailrank  YahooMyWeb 
Best Tips
Security Scanner
Security Categories
Advertise With Us!
Latest Viruses / Threats
Downloads
RSS / Atom Feeds
Identity Theft - Phishing : Beware of New Identity Theft Gozi Trojan
Posted by Max on 2007/5/22 12:30:00 (751 reads)
Identity Theft - Phishing

 A new, stealthier version of a previously known Russian Trojan named Gozi has been released on the Internet since April 17 and has already stolen identity data from more than 2,000 home users worldwide.
The compromised data includes bank and credit card account numbers (including card verification value codes – CVV2 Data), Social Security numbers and online payment account numbers as well as usernames and passwords. As with its precursor, the new version of Gozi is designed to steal information from encrypted Secure Sockets Layer (SSL) streams and send the stolen information to a server in Russia.

The variant was discovered by Don Jackson, a security researcher at Atlanta-based SecureWorks Inc. who also discovered the original Gozi Trojan horse back in January.


Two core "enhancements"
According to Jackson, the new version is very much alike to the original Gozi code in its purpose, but features two core enhancements. One of them is its use of a new and up till now unseen "packer" utility that encrypts, mangles, compresses and even deletes portions of the Trojan horse code to evade detection by standard, signature-based antivirus tools. The original Gozi, in contrast, used a fairly commonly known packing utility called Upack, which made it slightly easier to detect than the latest version.

This version of Gozi also has a new keystroke-logging capability for stealing data, in addition to its ability to steal data from SSL streams. According to Jackson, the keystroke logger appears to be activated when the user of an infected computer visits a banking Web site or initiates an SSL session. It is still unclear how exactly the keystroke logger knows to turn itself on and capture information, Jackson said.

Apart from those two differences, the variant is identical to Gozi, Jackson said. The Trojan horse takes advantage of a previously fixed vulnerability in the iFrame tags of Microsoft Corp.'s Internet Explorer to infect systems. Users typically appear to be infected when visiting certain hosted Web sites, community forums, social networking sites and those belonging to small businesses.

A service provider steps in
The server to which the stolen data was being sent to was located on a Russian network. The upstream Internet service provider for the network was a company based in Panama, Jackson said. After being informed about the Gozi Trojan horse and its data cache, the service provider appears to have "no-routed" the destination, meaning the rogue server has effectively been cut off from the Internet, he said.

SecureWorks has also contacted law enforcement authorities and informed them about the data cache, Jackson said. In addition, SecureWorks has made a signature for detecting the Gozi version available to other vendors so they can include it in their antivirus products, he said. So far, about 15 out of the top 30 providers of antivirus tools have incorporated the signature into their products and are able to detect and stop Gozi with varying degrees of efficiency, he said.




Other articles
2008/8/21 15:52:01 - BitRoll and Torrent101 Used to Distribute the Lop Adware
2008/8/20 15:06:33 - FRAUDFacts Helps You Fight Identity Theft and Fraud for Life
2008/8/13 16:42:03 - 10 Million Zombies Are Spreading Spam and Malware Every Day
2008/8/11 9:03:35 - Nearly $8.5 Billion Lost by US Consumers because of Online Threats
2008/8/8 6:35:36 - EDS' Eight Tips for Consumers to Protect Themselves from Identity Theft

The comments are owned by the poster. We aren't responsible for their content.