Researchers from Trusteer have discovered a new Banking Trojan called “Kronos” being sold on a Russian Underground forum.
The malware sells for $7,000, and its developers are offering a one-week trial for $1,000. The trial period includes full access to the command and control server, without any restrictions.

Like other banking Trojans, the new malware can steal login credentials and perform HTML Injection (C&C).
Kronos operates as a rootkit (Ring3) and has capabilities that allow it to defend itself from other malware and antivirus. It runs on 32 and 64 bit operating systems.
As mentioned above, it is designed to evade antivirus software and bypass Sandbox. It communicates with the C&C server using encryption.
Trusteer said it has not yet analyzed any samples of the malware, and that all the information it published is based on the advertisement for the “product” posted on the underground forum.
