2011年3月18日星期五

ZeuS in the Mobile is back

Yesterday, Polish Security Consultant and blogger Piotr Konieczny wrote (Polish) about a new wave of ZeuS trojan attacks. This time, it took place in Poland and it was directed against customers of ING Bank.

The samples used in this attack run on a number of platforms: Trojan-Spy.Win32.Zbot.bbmf for Windows, Trojan-Spy.SymbOS.Zbot.b for Symbian and Trojan-Spy.WinCE.Zbot.a for Windows Mobile. Yes, this time ZeuS in the Mobile (ZitMo) targets users of Windows Mobile smartphones too.

This attack was very similar to the first ZitMo attack which happened at the end of September 2010. Users infected by the Windows versions of the Zbot trojan were also asked to enter their cell phone number and smartphone model for a ‘certificate update’. After that, an URL with the link to the ‘certificate update’ (which is actually a ZeuS trojan for particular smartphone platform) was sent in a SMS to the infected customer. If users would have downloaded and installed this malicious file, their incoming SMS messages (with mTAN authentication codes also) would have been resent silently to a predefined cell phone number.

free malware malware spyware malware spyware removal

没有评论:

发表评论