Variants of the notorious ZeuS/ZBOT are back, with a vengeance. There has already been an increase in the activity of a different version of the malware. In its 2013 Internet Threat Forecast published in January by security firm Trend Micro, they predicted that cybercrime would be characterized by the return of old threats that would come back in improved form. Since the first quarter of the year, this publication has proven true, after threats such as CARBERP and the Andromeda botnet.
We can now include the ZeuS/ZBot malware among the old, but upgraded threats that have appeared in recent months according to the Trend Micro Smart Protection Network
ZBot variants increased in early February and continue to be active to this day. In fact, as the chart shows, they peaked in mid-May 2013. These malware programs are designed to steal credentials from users, which can be banking login credentials and other personal information.
The first generation of ZBot variants creates a folder in %System% where it stores stolen data and configuration files. It usually copies itself to the same folder to have a backup of the malware. These versions of ZBot modify the Windows hosts file to prevent victims from accessing relevant security websites. The strings appended to the hosts file can be seen in the configuration file. An example of older versions of ZBot include TSPY_ZBOT.SMD and TSPY_ZBOT.XMAS.
Current ZBot variants have been observed to create two randomly named folders in %Applications Data%. One folder contains a copy of the folder containing ZBot while the other folder contains the encrypted data. An example is TSPY_ZBOT.BBH, which was found globally above and recorded by the Smart Protection Network.
The new variants send DNS queries to random domains. The difference in one variant (GamOver variant) is that it opens a random UDP port and sends encrypted packets before sending DNS queries to the random domains.
But how can this malware steal your credentials?
The ZBot malware connects to a remote location to download an encrypted file containing its settings.
Figure 2. Screenshot of ZBot communication to the C&C server,
We can see the following information if the configuration file is decrypted:
- A location where an updated copy of the malware is stored.
- List of websites to monitor.
- Place that will send the stolen data.
These configuration files contain the banks and other financial institutions that ZBOTs wants to monitor from browsers.
Since the configuration files are downloaded from remote locations, their contents can change at any time.
Trend Micro solutions for ZBot variants
There are many fields that can be detected, such as:
- First, the malware tries to write to the “Userinit” registry of HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
- Second, detecting the remote site's callback routine at runtime, as it obtains its configuration file
- Finally, the detection of the site that is programmed to send the stolen data, or download an updated copy of itself.
Conclusion
What can we learn from the new ZeuS/ZBOT? Old threats like ZBot can always make a comeback, because the criminals who run them profit from them. They seek banking and other personal information from users and it is a lucrative business. It is important to be extra careful when opening emails or clicking on links. Of course, our systems should always be up to date with the latest security releases from security vendors and use reliable antimalware solutions.
To learn more about how cybercriminals steal information, check out the infographic below.
Click to enlarge



