HomeSecurityNew Gozi Trojan version bypasses behavioral biometric defenses

New Gozi Trojan version bypasses behavioral biometric defenses

The latest version of the Gozi banking trojan, currently under development, comes with a few tricks up its sleeve, including an increased role for malicious human actors during the infection process and the ability to bypass some behavioral biometric defenses.

This new Gozi version is active in countries such as Japan, Spain and Poland and targets financial institutions such as PayPal, CitiDirect BE, ING Bank, Société Générale, BNP Paribas, Bank of Tokyo and many others.

New Gozi Trojan version bypasses behavioral biometric defenses

According to buguroo, this version of Gozi is not related to GozNym, another banking trojan that emerged from Gozi source code that was leaked online in 2015.

This new version of Gozi uses Web injection attacks, like the first generation of Gozi. GozNym also used Web injection attacks, but started redirection attacks in June.

Web injection attacks rely on malicious DLLs that are loaded into the browser to display overlays on top of the website when the victim visits a banking portal supported by trojan modules.

Each Gozi module supports a Web injection package that displays a fake page on top of the original banking portal. It is basically a Web injection module for each targeted financial institution.

These modules can collect login credentials for the banking portal during the login process, but they can also hijack the payment page.

Some of these Web injection attacks even operate in real time, with a fraudster on the other side deciding which “pretext” account to redirect stolen funds to and in what amount. Unfortunately, there is cyber-crime infrastructure for this kind of work on the Dark Web.

In recent Gozi infections, buguroo says he has observed such behavior. Gozi is not the first trojan to use human operators when engaging in Web injection attacks.

For smaller accounts, the Gozi trojan is still automated, choosing a random “pretext” account and a fixed payment amount, but when the trojan infects high-value targets, a human operator takes over and decides which “pretext” account the cash will be transferred to, along with the largest amount, if possible. This is done in cases where the scammers have infected business accounts.

Banks are constantly battling banking trojans like Gozi and their sophisticated cyber-crime infrastructure. Some of them have developed behavioral biometric solutions that record the speed and pace at which users type and move the cursor between input fields. Security researchers say this new version of Gozi records these values ​​as well.

“The malware uses these values ​​to fill in the necessary fields to perform the fraudulent transfer, which looks like an attempt to bypass biometric-based protection systems,” buguroo explains.

Details about this new Gozi variant will be presented at the Black Hat USA 2016 in Las Vegas. Details include analysis of Web injections, C&C communication techniques, and a comparison with the Gootkit trojan.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS