HomeSecurityCutwail Botnet Targets Swiss Users with Tinybanker Trojan

Cutwail Botnet Targets Swiss Users with Tinybanker Trojan

Malicious email messages started to «hit» the inbox of users in Switzerland on Tuesday, researchers say, and contain a version of the banking Trojan Tinybanker.

Cutwail Botnet Tinybanker Trojan

A security researcher reports that the origin of these messages is the spam botnet, a network of infected computers commandeered to distribute different types of malware.

Also known as Tinba, Illi , and Zusy, Tinybanker gained popularity as the smallest banking Trojan, measuring around 20KB in size. However, despite its small size, the malware also stood out for its functionality, which approached that of larger threats of the same kind.

According to Abuse.ch, the version of Tinba currently distributed via Cutwail does not rely on a domain generation (DGA) to obtain the addresses of command & control (C&C) servers. Instead, the IP addresses are pre-assigned to the malware.

This detail is very useful in combating the threat because, if the C&C servers are disabled, cybercriminals will no longer have access to the data stolen from the compromised systems.

Currently, two of the four C&C servers have been disabled and the others are pointing to machines located in Russia.

Three different spam attacks have been observed by the security researcher, one pretends to be from Bluewin (a major Internet provider in Switzerland), the second presents itself as an MMS notification claiming to come from Orange (a telecommunications provider), while the third appears to be a job application.

All communication has been created to lure the recipient and open the contents of an attached file.

Cutwail also distributes the banking Trojan Dyre

While analyzing the IP addresses used to send the messages, the researcher discovered that they all belong to computers in the Cutwail botnet.

Earlier this week, Symantec also detected aggressive activity related to Cutwail as researchers recorded bursts of spam being sent to potential victims.

They said these "outbreaks" lasted just a few minutes and targeted millions of users either received a version of a different banking Trojan, Dyre (also known as Dyreza) or were directed to a phishing.

An interesting change in the way the attack was carried out observed by the researchers was that the messages do not contain a malicious attachment, as is usually the case, but instead include a link that leads to the download of the malicious software.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS