Your ad here
Powered by MaxBlogPress  

Labor to keep alive in your breast that little spark of celestial fire called conscience.
-George Washington

lomo-banner
Your ad here

« Windows Vista Beta 1 and A File Infector Against It (Updated)
» World of Warcraft Targeted by Malware

Tech Security

The BANCOS Phishing Spyware

10.18.05 | Comment?


If you're new here, you may want to subscribe to my RSS feed. Thanks for visiting!

We had seen this before, in a spoofed Yahoo signin page. Now let’s tackle a more insidious phishing attempt - stealing bank account information.

A family of spyware is famous for stealing bank account information - the aptly named BANCOS/BANKER spyware family. This spyware has been around the bush for a long time, and has victimized a lot of unsuspecting users through the years. Though most of them only target Brazilian banks, we cannot tell when it will hit other banks.

The BANCOS family utilizes several methods in stealing. The most common are:

  • Keylogging - when a user visits any of the target sites, the spyware logs the keystrokes
  • Spoofed login page - when a user visits any of the target sites, the spyware displays a login page that is eerily similar to the login page of that site

So the routine is simple: (1) Monitor user’s Web activity and sites visited; (2) when a target site is visited, execute stealing method; (3) send stolen data to a remote user.

The spyware usually monitors sites visited by either checking the browser’s title bar for certain strings, or monitoring IE access to several sites. Once a match is found, it executes the stealing routine. Afterwards, it sends the stolen data in several ways, the most common is to send via email using the spyware’s builtin SMTP engine.

As stated earlier, BANCOS/BANKER targets Brazilian banks. For now.

Symantec’s generic description for BANCOS is here. A typical Trend Micro description (with pictures to boot) is here.

Like my article? Leave a tip! Or, treat me to a cup of coffee!

Visit the AWBHoldings.com Online Store!


If your comment is eaten by Akismet or just went somewhere else, please let me know. You can either leave a message at the chat box at the lower left, or via the contact page. Thanks!

RSS feed | Trackback URI

Comments »

No comments yet.

Name (required)
E-mail (required - never shown publicly)
URI
Subscribe to comments via email
Your Comment (smaller size | larger size)
You may use <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> in your comment.

Comments will be sent to the moderation queue.


« Windows Vista Beta 1 and A File Infector Against It (Updated)
» World of Warcraft Targeted by Malware