Dyre Banking Trojan Sent to Users via Blitz Spam Attacks – Operators of the Cutwail spam botnet changed their tactics and began sending malicious emails targeting millions of users.
Security researchers noticed that instead of malicious attachments, emails sent by the botnets contain links leading to the Upatre malware , which leads to the Dyre banking Trojan .
The lure follows a common pattern, as the subject of the message refers to an important announcement included in the message and claims to come from a legitimate company that may or may not be related to the potential victim.
In general, it has been observed that emails related to some kind of financial issue (tax return, invoice, bank account, fines) attract the user's attention, making them vulnerable to a breach.
Researchers from Symantec report that in some cases the links lead to phishing websites that appear to be financial services log-in websites provided by different organizations.
“The goal of the email, however, is to trick the recipient into clicking on the URL , which will either lead to malware or a phishing website. The attacks use the same URL from compromised legitimate domains,” says Nick Johnston of Symantec.
In a blog post on Wednesday, he notes that after accessing the malicious link, the user is directed to a page that references an external JavaScript. The victim's web browser is verified, and if it matches the profile, then the next step of the attack begins: the victim receives Upatre , which downloads Dyre, also known as Dyreza.
Johnston notes that the URLs listed appear to point to legitimate JQuery files , which are in HTML code . However, they do not lead to static content, as is usually the case, but to a dynamic web service that responds to requests.
The researcher reports that the returned JavaScript contains JJEncode , which does not work in all browsers . However, even if the obfuscation is removed, the code still contains incoherent variables and function names.
The threat requires user interaction, but since the user has already followed the malicious link to download the supposed file containing financial information, it is safe to assume that the user will also extract the file's contents and execute it.

