Attacks/Breaches

12/20/2017
05:36 PM
Kelly Sheridan
Kelly Sheridan
Slideshows
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

9 Banking Trojans & Trends Costing Businesses in 2017

New Trojans appeared, old ones resurfaced, and delivery methods evolved as cybercriminals set their sights on financial data.
Previous
1 of 10
Next

(Image: Muratart via Shutterstock)

(Image: Muratart via Shutterstock)

Banking Trojans have been a recurring theme in security news this year as criminals find new ways to steal money and data from their victims.

"We have started to see the re-emergence of banker Trojans," says Bogdan Botezatu, senior e-threat analyst at Bitdefender, noting that banking Trojans had their heyday between 2012 and 2013. "But we could have sworn the trend was otherwise."

It's interesting to see banking Trojans resurface because of the resources they need to work. Unlike comparatively simple attacks like ransomware, banking malware requires several players and is difficult to launch and monetize. Botezatu suggests the rise could be attributed to both code leaks of other banking Trojans and an oversaturation of the ransomware market.

Many of the banking Trojans we've seen this year are reminiscent of those we've seen in the past. Others are old threats being distributed in new ways, targeting new victims.

Terdot, a banking Trojan first seen in October 2016, takes its inspiration from source code of the Zeus banking Trojan following Zeus' source code leak in 2011. IcedID, another new banking Trojan that emerged in September, shares traits with Gozi, Zeus, and Dridex.

"Overall, this is similar to other banking Trojans, but that's also where I see the problem," says Limor Kessem, executive security advisor for IBM Security, of IcedID. It's rare to see banking Trojans that don't share qualities with existing variants. Attackers are copying one another and adding new features like anti-evasion techniques to further advance the malware.

Here, we look back on the new and evolved ways banking Trojans targeted victims in 2017. Any threats we missed that should've made the list? Which do you think will stick around next year? Feel free to leave your thoughts in the comments and read on for more.

 

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Previous
1 of 10
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Crowdsourced vs. Traditional Pen Testing
Alex Haynes, Chief Information Security Officer, CDL,  3/19/2019
BEC Scammer Pleads Guilty
Dark Reading Staff 3/20/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Well, at least it isn't Mobby Dick!
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
The State of Cyber Security Incident Response
The State of Cyber Security Incident Response
Organizations are responding to new threats with new processes for detecting and mitigating them. Here's a look at how the discipline of incident response is evolving.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-20165
PUBLISHED: 2019-03-22
Cross-site scripting (XSS) vulnerability in OpenText Portal 7.4.4 allows remote attackers to inject arbitrary web script or HTML via the vgnextoid parameter to a menuitem URI.
CVE-2019-1716
PUBLISHED: 2019-03-22
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 7800 Series and Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code. The vulnerability ...
CVE-2019-1763
PUBLISHED: 2019-03-22
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to bypass authorization, access critical services, and cause a denial of service (DoS) condition. The vulnerability exist...
CVE-2019-1764
PUBLISHED: 2019-03-22
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack. The vulnerability is due to insufficient CSRF protections for the ...
CVE-2019-1765
PUBLISHED: 2019-03-22
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an authenticated, remote attacker to write arbitrary files to the filesystem. The vulnerability is due to insufficient input validation and file-level permis...