HomeSecurityZeus Trojan reappears with valid digital signature

Zeus Trojan reappears with a valid digital signature

zeus-malware-banking-trojan

A new dangerous variant of the Zeus Banking Trojan has been detected by Comodo, which is signed by a stolen Digital Certificate, belonging to Microsoft Developer, to avoid detection by Web browsers and anti-virus systems.

Every Windows computer is set to accept software "signed" with Microsoft digital certificates, an extremely sensitive certificate.

Cybercriminals somehow managed to compromise the valid Microsoft certificate, used it to trick users and administrators into trusting the file. Since the executable file is digitally signed by Microsoft, an antivirus tool would not be able to detect it as malicious.

Digitally signed malware received a lot of attention last year. According to reports, more than 200,000 unique malware discovered in the past two years had valid digital signatures.

A Comodo user sent a sample of the malware that tries to trick the user disguised as an Internet Explorer file, with a valid signature, issued by "Isonet ag".

malware-microsoft-digital-cert

When executed, the malicious file installs itself, without being detected as a virus, and also attempts to download the following rootkits:

lovestogarden.com / images / general / TARGT.tpl

villaveronica.it / images / general / TARGT.tpl

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS