HomeSecurityGozNym Banking Trojan hits US with redirect attacks

GozNym Banking Trojan hits the US with redirect attacks

GozNym, a banking trojan discovered just two months ago, has added a new trick to its arsenal and is using it to target high-end corporate banking services in the US.

IBM's security team, X-Force, discovered GozNym in April 2016, when it detected the trojan targeting customers of financial institutions in the US and Canada.

GozNym Banking Trojan hits the US with redirect attacks

In its initial versions, the trojan used a technique called “Web injections,” which relies on a malicious DLL loaded into the user’s browser to display overlays on top of the page when visiting a banking portal supported by the trojan’s modules.

Web injection attacks are common, and GozNym's Web injections are inherited from the Gozi banking trojan. In fact, the name GozNym comes from the combination of Gozi and Nymaim, a malware dropper.

Two weeks after IBM published its findings on GozNym's tactics, the crooks behind the malware have added a new idea to their modus operandi.

GozNym began using a technique called a “redirect attack.” The trojan initially deployed this attack only in Poland, targeting 230 URLs belonging to 17 financial institutions.

A redirection attack occurs when malware redirects the user to a fake banking portal, operated by fraudsters. To trick users, attackers use malware to display the correct URL and the bank's real SSL certificate in the browser's address bar.

Redirect attacks have been made famous by banking trojans, such as Dyre and Dridex, but to a lesser extent.

They are incredibly difficult to detect and are the base of cybercrime groups because they are expensive to run, both financially and in terms of human resources.

GozNym operators need both the server infrastructure to host all these banking portal copies and the programmers to constantly update the fake websites to resemble the original ones.

“In most cases, GozNym redirects to the bank’s homepage, but that’s not the only page the malware can redirect to,” explains IBM’s Limor Kessem. “There are cases where other pages redirect to a copy of GozNym to force the victim to enter their login credentials.”

After activity from the Dyre botnet began to decline, GozNym and Dridex are the only banking trojans that perform redirect attacks.

According to IBM statistics, GozNym ranks as the fifth most active banking trojan botnet for the first months of 2016. Dridex takes second place.

statistics-banking-trojan

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS