HomeSecurityCridex banking malware uses Gameover Zeus eavesdropping technique

Cridex banking malware uses Gameover Zeus interception technique

Cridex-Banking-Malware-Variant-Uses-Gameover-Zeus-Thieving-Technique.jpgSecurity researchers have discovered a new variant of the Cridex banking malware, which relies on P2P infrastructure to communicate with Command & Control (C&C) servers and is mainly used to steal banking credentials.

According to security researchers at IBM X-Force, the malware performs HTML injections to achieve its goals, which are similar – and in some cases identical – to the HTML injections of Gameover ZeuS (GOZ).

The use of this technique makes the malware more sophisticated and effective. It is suspected that the Cridex perpetrators used reverse engineering on a GOZ sample and copied the HTML injections, then adapting them to the needs of their own software.

Researchers report that Cridex's new capabilities lead to more effective bypassing of security measures, such as two-factor authentication or IP reputation.

The new malware variant works as follows:

When it infects a computer, Cridex waits until the user gains access to their bank account. When this happens, the malware automatically redirects victims to a fake website that mimics the bank and asks them to enter their account login details.

The malware then connects to the bank's website in real time and logs in with the stolen credentials, using the IP address of the infected computer, so that the malicious activity cannot be detected by the banking systems.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS