Endpoint

7/26/2018
05:10 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Kronos Banking Trojan Resurfaces

Re-emergence of malware consistent with overall surge in banking malware activity this year, Proofpoint says.

Like a bad penny, the notorious Kronos banking Trojan has turned up again after disappearing from the threat landscape for well more than a year.

Security vendor Proopoint this week said it had recently observed a new variant of Kronos being used in separate campaigns against users in Germany, Japan, and Poland. A fourth campaign involving the malware appears to be in the works and is currently being tested.

The new variant is very similar to older versions except for the fact that it now uses the Tor anonymizing network for hiding its command-and-control (C&C) server.

Otherwise, the new version uses the same Windows API hashing techniques and hashes, encryption technique, C&C encryption mechanism, Zeus webinject format, and C&C panel layout. The new malware even includes a self-identifying string labeling it as Kronos.

The sudden reappearance is consistent with a broader resurgence in malicious activity involving banking Trojans so far this year, says Sherrod DeGrippo, director of emerging threats at Proofpoint. "We can only speculate on the reasons for the disappearance [of Kronos], but banking Trojans have come to dominate the threat landscape over the first half of 2018," she says.

One reason could be that ransomware has fallen out of favor among cybercriminals because of the volatility in prices of the cryptocurrencies used to make ransom payments, DeGrippo notes. Development activity around banking Trojans has surged even as threat actors' interest in ransomware has declined.

According to Proofpoint, a recent advertisement in an underground forum suggests that the authors of the latest Kronos variant are attempting to pass it off as a new banking Trojan dubbed Osiris. The description for Osiris — including the fact that it is written in C++, has keylogging and form-grabbing capabilities, and uses Tor and Zeus-formatted webinjects — suggests that the malware is simply the latest Kronos variant with a new name.

"This is essentially a rebranding of the old version of Kronos," DeGrippo says. "The use of Tor is really the only new feature of significance."

Kronos first surfaced in 2014 and is designed to steal the credentials and other information people use to log into their online banking accounts. The malware uses man-in-the-browser (MITB) techniques and webinjects to stealthily modify the Web pages of the financial institution a user might be attempting to log into in order to grab that person's credentials and later use it to steal money from the account.

The FBI has accused British security researcher Marcus Hutchins — the individual credited with stopping the WannaCry outbreak last year — of developing Kronos and distributing it to others between 2014 and 2015. Hutchins was arrested in August 2017 and is currently awaiting trial in the US on charges related to this and another malware kit dubbed Upas.

Kronos is similar to several other successful banking Trojans in many ways. But it does appear to have a habit of re-emerging every now and then, DeGrippo says. "Like Dridex, Zeus, Ursnif, and other bankers with substantial staying power, it comes down to malware authors and threat actors who are willing to invest in development and maintenance, as well as distribution and configuration of injects," she says.

The campaigns in Germany, Poland, and Japan that Proofpoint recently observed all involve the new Kronos variant but use slightly different techniques to infect end user systems. In Germany, users are being targeted via emails purporting to be from financial companies and seemingly pertaining to account updates and other accounts reminders. The emails contain Word documents with malicious macros that, if enabled, download the new Kronos variant.

The campaign in Japan has involved the use of a malvertising chain to send victims to a site with malicious JavaScript injections that redirect them to the RIG exploit kit, which then dumps the new Kronos variant on their systems. Polish users, meanwhile, are being targeted with emails containing a malicious attachment that, when executed, exploits CVE-2017-11882, a memory corruption issue in Microsoft Office, to download Kronos. Like the campaign in Germany, the emails in Poland come with subject headers designed to fool recipients into opening the attachments.

Banking Trojans are very hard for banks themselves to address since the malware operates on the client side and typically uses MITB-style attacks, DeGrippo says.

Much of the onus must fall on individuals to prevent infection in the first place. "While banks can implement two-factor authentication for some degree of protection, even this is not a panacea for modern, sophisticated banking Trojans and is often considered too burdensome by consumers," she says.

Related Content:

 

 

 

Black Hat USA returns to Las Vegas with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
'PowerSnitch' Hacks Androids via Power Banks
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/8/2018
Windows 10 Security Questions Prove Easy for Attackers to Exploit
Kelly Sheridan, Staff Editor, Dark Reading,  12/5/2018
Starwood Breach Reaction Focuses on 4-Year Dwell
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/5/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: I guess this answers the question: who's watching the watchers?
Current Issue
10 Best Practices That Could Reshape Your IT Security Department
This Dark Reading Tech Digest, explores ten best practices that could reshape IT security departments.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-20029
PUBLISHED: 2018-12-10
The nxfs.sys driver in the DokanFS library 0.6.0 in NoMachine before 6.4.6 on Windows 10 allows local users to cause a denial of service (BSOD) because uninitialized memory can be read.
CVE-2018-1279
PUBLISHED: 2018-12-10
Pivotal RabbitMQ for PCF, all versions, uses a deterministically generated cookie that is shared between all machines when configured in a multi-tenant cluster. A remote attacker who can gain information about the network topology can guess this cookie and, if they have access to the right ports on ...
CVE-2018-15800
PUBLISHED: 2018-12-10
Cloud Foundry Bits Service, versions prior to 2.18.0, includes an information disclosure vulnerability. A remote malicious user may execute a timing attack to brute-force the signing key, allowing them complete read and write access to the the Bits Service storage.
CVE-2018-15805
PUBLISHED: 2018-12-10
Accusoft PrizmDoc HTML5 Document Viewer before 13.5 contains an XML external entity (XXE) vulnerability, allowing an attacker to read arbitrary files or cause a denial of service (resource consumption).
CVE-2018-16635
PUBLISHED: 2018-12-10
Blackcat CMS 1.3.2 allows XSS via the willkommen.php?lang=DE page title at backend/pages/modify.php.