Malware experts at Symantec have discovered a new strain of the infamous Carberp Trojan , designed to steal banking credentials and other sensitive data from users.
The security experts at Symantec, discovered on December 15 a new malicious campaign for the distribution of this new Carberp Trojan variant.
The continuous evolution of Carberp, just like other popular malware, such as the Zeus Trojan, was made possible because the source code had been available on underground sites since June 2013. The first spam campaign distributing the new version of the malicious script, identified as Trojan.Carberp.C, was found by Symantec on December 15, just one day after the Trojan was completed.
The spam mail, which claims to concern a payment reminder, includes a malicious link that appears as an invoice (e.g., invoice. [random numbers] _2014.12.11.doc.zip). The Trojan dropper is packed with Visual Basic scripts and is attached to the spam mail as a ZIP file.
Carberp.C is primarily designed to collect banking credentials and other sensitive information, but this variant also includes a collection of plugins that are injected into a newly created process (svchost.exe) to give the attacker further capabilities.
One of the plugins examined by the researchers is capable of stealing sensitive data from the victim's web browsers. The new variant appears very effective, and can infect 32-bit and 64-bit systems and includes plugins for several CPU architectures.
As soon as the victim opens the ZIP file, the dropper injects code into a Windows process, and decrypts and decompresses embedded 32-bit or 64-bit modules, depending on the operating system type.
Most infections, with the Carberp Trojan up to now, have been discovered in Australia and the U.S.

