Most Popular Stories
- Apple's iPad 3 will be unveiled first week of March, says report
- Chrome 17's new features enhance speed, security
- Nearly half of U.S. businesses to have mobile apps this year
- Microsoft: How Windows 8 on ARM will be different
- Microsoft's Patch Tuesday for February has 9 security bulletins
- Why people don't really plan website migrations
Events
- CIO Healthcare Summit
March 11-14 — Scottsdale, AZ - Ready to meet the next-generation of business?
March 4-6 2012 — San Francisco, CA - Northwestern University Master's in Information Systems
- MDSL Telecom Expense Management Roadshow
Feb 21–23, 2012 — New York, Houston, Chicago
Sponsored Links
Free Newsletter
HOT TOPICS >> The tech world's top flops and fiascos of 2011 | Top 8 features in Windows 8 | Paul's Q&As
INDUSTRY >> Healthcare IT | Government IT | Financial Services IT | Biotech IT | Compliance IT
Free Newsletter
Latest News
Popular Topics
Whitepapers
- Whitepaper: Integrated Analytics and WCM Can Improve Performance & ROI
- Enterprise Digital Assistant Leverage in the Emerging Mobile Enterprise
- Ringing in Growth - How Service Bureau-based Outsourcing is a Win-Win Approach for Communications Service Providers
- The Shortcut Guide to Secure, Managed File Transfer
- Innovative Solutions for Database and DBA Management
- Making Change Stick
The growing problem of banking Trojans
A new Trojan has been discovered swiping credentials of customers across various banks in the United States. Discovered by researchers at SecureWorks, the Bugat Trojan bears similar features as other better-known banking Trojans like Clampi and Zeus, though incidences of Bugat appear to be low for now.
SecureWorks security researcher Jason Milletary, blogged, "The emergence of Bugat reinforces that there is a strong demand for new malware to commit financial credential theft and that ACH (Automated Clearing House) and wire fraud remains a profitable venture for criminals."
Banking Trojans allow remote attackers to perform sophisticated man-in-the-middle attacks on web sessions--a technique that was once the domain of computer science textbooks or hacking demonstrations. Data from Neustar indicated however, that U.S.-based SMBs are losing an average of $100,000 to $200,000 per day to such attacks targeting online banking activities.
Network traffic to banking sites are surreptitiously channeled via the cybercriminal, and fraud could occur by swapping account numbers when transferring funds. Alternately, the Trojan could request for the one-time-code used by most banks when none is required, which is then used to log in from another location and wire funds out.
Additionally, banking Trojans are also known to utilize the use of SSL encryption to deter detection on the network, and widely distributed via botnets. Ultimately, protection from them is not impossible, but it requires that banks implement more robust measures.
For more on this story:
- check out this article at Dark Reading
- check out this article at eWeek
Related Articles:
Rogue malware is money spinner for scammers
At least one trojan using Facebook as a command channel
Industry-wide phishing attack strikes thousands
Report: Trojan attacks up, phishing down in '09
Related Stories
- Evidence of Zeus Trojan found in majority of Fortune 500 companies
- Intel buys XML router company
- Researchers uncover BIOS malware Trojan.Mebromi in the wild
- Zeus code being used for new banking malware
- Dropbox accounts left completely unprotected for four hours
- Mobile malware highlights continuing threat of Trojans
- Apple support reps told to ignore Mac Defender malware
- LastPass precautionary password change sows confusion
- New ransomware tricks with bogus Windows activation
- Aruba Networks unveils MOVE architecture; launches wired and wireless products
Home
| Subscribe | Advertise | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2011 FierceMarkets. All rights reserved. |
![]() |




