HomeSecuritySwiss Banks Targeted by Dyre Trojan

Swiss Banks Targeted by Dyre Trojan

Trojan Horse

The latest variant of the Dyre/Dyreza banking Trojan comes with an extensive target list that includes financial institutions in Switzerland and is spread to victims' computers via a Windows vulnerability exploited by the cyber-espionage group Sandworm.

The Trojan is spread via spam emails that include a PowerPoint attachment that contains an exploit for the CVE-2014-4114 vulnerability in the Windows operating system. The vulnerability is present in OLE (Object Linking and Embedding) and allows downloading and executing INF files.

OLE is the technology that facilitates the exchange of data between various programs and is integrated into Microsoft Office components.

Researchers from security consulting firm CSIS noticed that the version of Dyre distributed via email campaign comes with an updated list of targets in the configuration file, including banks in Switzerland.

Dyre is designed to steal financial data, as it can be exploited in man-in-the-middle (MitM) attacks that intercept communication between the customer and the bank, without raising suspicions on either side.

According to the researchers, this particular version of the malware establishes a communication with a host computer located in France.

The malware appears to have gained popularity among cybercriminals, as it has been used in multiple attacks recently.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS