HomeSecurityA combination of Zeus and Carberp Trojans discovered

A combination of Zeus and Carberp Trojans discovered

Bolek is the name of a new banking trojan that was born from the leaked source code of the Carberp and Zeus banking trojans. Malware developers have combined their code to create a brand new threat that is currently preying on Russian bank customers.

CERT Poland researchers first spotted the trojan in mid-May when they were investigating a phishing campaign originating from their country, noticing a slight similarity between Bolek and Carberp's KBot module.

A combination of Zeus and Carberp Trojans discovered

Two days later, US security firm PhishMe expanded on the CERT-PL findings with a comprehensive report on how Bolek operates, again noting visible similarities between Bolek and Carberp.

More reports followed, first from Russian antivirus vendor Dr.Web, and then from Arbor Networks, both in early June. While the Arbor report focused on Bolek's C&C server communications, the Dr.Web report included an analysis of how the trojan operated, along with similarities between Bolek, Carberp, and even the ancient Zeus banking trojan.

Dr.Web says the trojan is fully equipped to target today's banking ecosystem. Bolek is able to steal login credentials from online banking applications by injecting itself into a Web browser process, can take screenshots of the user's screen, can intercept Web traffic, can snoop on keystrokes, or create a local proxy to transfer files to the infected machine.

Bolek can target Microsoft Internet Explorer , Google Chrome, Opera , and Mozilla Firefox browsers and comes with a built-in version of Mimikatz, a known password dumping application

The part that Bolek borrowed from Carberp includes a custom virtual file system, which the trojan uses to store various files required for its operation, in order to hide them from security software.

From Zeus, Bolek borrowed its powerful Web injection mechanism that allows it to exploit browser processes and take over the entire website when the user visits an online banking portal.

Furthermore, the trojan can infect both 32-bit and 64-bit Windows machines, and when launched, it can initiate a reverse connection to the attacker via RDP (Remote Desktop Protocol).

Despite all these deadly features, this was not the most interesting feature, Dr.Web researchers emphasize. After infecting a target, Bolek administrators can send a command to the trojan and activate a self-propagating mechanism similar to a worm.

This feature allows the Trojan to spread to other files on the same file system or to USB drives. Bolek has the ability to infect Windows , which if moved to other computers, can help the trojan spread to other targets.

«The main purpose of Trojan.Bolik.1 is to steal confidential information», the researchers at Dr.Web explain. «[The] functions and architecture of Trojan.Bolik.1 are highly advanced, which makes it very dangerous for Windows users»

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS