HomeinetNeverquest banking malware more dangerous than Zeus trojan

Neverquest banking malware more dangerous than Zeus trojan

imagesFor over 5 years, Trojan Zeus was the undisputed king of banking malware. Once the Trojan was loaded onto a victim's computer, it could:

  • Detect when the user was providing banking information in the web browser.
  • To steal passwords and other login details.
  • Encrypt the stolen information and send it to the attacker's server.

Zeus was also the first malware to be sold under license. For the right price, anyone could use it.

Zeus has remained active to this day, although its code was published online in 2011. Unfortunately, security experts are already warning about a new malware that makes Zeus look like a game. Neverquest is raising the bar for online banking malware.

How it works:

Like Zeus, Neverquest is a Trojan. The attacker introduces Neverquest to the victim's computer via social media, email, or some file transfer. According to the security blog 'Threat post', Neverquest replicates itself similarly to the Bredolab botnet (Before the Bredolab Botnet was dismantled, it consisted of 30 million computers!).

If the victim's computer targeted by the Neverquest loader is exposed to an exploit, the malware is installed. Then, Neverquest starts observing what the user types in the web browser. If it recognizes a predefined financial term, it checks the domain name of the website (Neverquest has hundreds of banking institutions in its database, so there is a high chance that it will recognize the bank's site).

Once Neverquest recognizes a bank site, it will transfer the login information to the attacker's main server. Once the victim's credentials are in the attacker's hands, he will be able to control the victim's computer using any VNC program and connect to the victim's banking website, where he will be able to transfer money and change the login information, 'locking out' the user.

One feature of Neverquest that Zeus did not have is that it can add new banking sites to its database. If the Trojan recognizes banking terms but not the domain, it will send the information back to the server and create a new entry, then update all infected computers.

Unfortunately, Neverquest is already available for sale. Unlike Zeus, which required skilled operators, Neverquest can be used by any beginner upon purchase.

As Kaspersky states on its blog, “Threats like Neverquest require more than just antivirus, users need a solution that secures their online transactions.” It also states that Neverquest is designed to steal data from various other sites, besides banks, such as Facebook, Twitter, Skype, Google.

member SecTeam  @ Walkin.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS