HomeSecurityVizom: New malware hijacks bank accounts

Vizom: New malware hijacks bank accounts

Vizom masquerades as popular "videoconferencing software", with meetings all taking place online due to the pandemic.

Researchers have discovered a new form of malware using remote overlay to hit bank account holders in Brazil.

The new variant of the malware, dubbed Vizom by IBM, is being used in an active campaign across Brazil designed to compromise bank accounts through online financial services.

Vision

On Tuesday, IBM security researchers Chen Nahman, Ofir Ozer, and Limor Kessem said the malware uses interesting tactics to stay hidden and compromise users in real time — namely, remote overlay and DLL hijacking techniques.

Vizom spreads through spam-based phishing campaigns and masquerades as popular video conferencing software – tools that have become vital for businesses and social events due to the COVID-19 pandemic.

Once the malware lands on a vulnerable Windows computer, Vizom will first hit the AppData directory to start the infection. By leveraging DLL hijacking, the malware will attempt to force the loading of malicious DLLs by naming its own Delphi-based variants with names expected by legitimate software in their directories.

By hijacking a system's "innate logic," IBM says the operating system is tricked into loading the Vizom software as a child process of a legitimate video conferencing file. The DLL is called Cmmlib.dll, a file associated with Zoom.

A dropper will then launch zTscoder.exe via the command line and a second payload, a Remote Access Trojan (RAT), will be extracted from a remote server – with the same hijacking trick performed on the Vivaldi web browser.

To establish persistence, browser shortcuts are compromised and regardless of which browser a user tries to run, the malicious Vivaldi/Vizom code will run in the background.

The malware will wait for any indication that an online banking service is being accessed. If the title of a webpage matches Vizom's target list, operators will be notified and can remotely log in to the compromised computer.

As Vizom has already developed RAT capabilities, attackers can take over a compromised session and overlay content to trick victims into giving up their bank account credentials.

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS