HomeSecurityDyre Banking Trojan Targets Businesses in the US

Dyre Banking Trojan targets businesses in the US

A new malicious email campaign is spreading the Dyre banking Trojan to US users via e-fax notifications, indicating that cybercriminals are targeting business computers rather than users.

Dyre Banking Trojan USDespite the fact that there is no technical advantage compared to email, electronic fax communication is still used in companies around the world to exchange documents in digital format rather than on paper.

Notifications for new faxes available to the user are sent to incoming e-mails from the e-fax and a download link is provided.

In the campaign detected by Bitdefender, the URL directs to a file containing an executable that appears as a PDF.

According to malware analysts from the anti-virus software company, the object is a downloader that downloads the Dyre banking Trojan, also known as Dyreza.

They observed that the campaigners adopted techniques to avoid detection of the malware. Cybercriminals rely on the technique of server-side polymorphism, which consists of automatically applying various obfuscation and encryption measures to the payload before it is downloaded from the malicious server, so that it appears unique.

Researchers report that within a single day, a batch of 30,000 malicious emails were sent from spam servers in the US, Russia, Turkey, France, Canada, and the UK.

During the investigation, experts found that the campaign was named “2201us,” a name that could refer to the date the attack began operating, namely January 22, as well as the targeted country, namely the United States.

They also discovered that the Trojan is activated on infected computers when the victim visits websites of trusted banks in the US, UK, Ireland, Germany, Australia, Romania and Italy.

It is common for businesses to open accounts at multiple financial institutions in order to complete their financial transactions more efficiently.

Dyre is based on the man-in-the-browser technique , connecting to the web browser. It intercepts traffic between the compromised system and the targeted banks and can manipulate the website content via real-time web injection .

Basically, attackers can provide the victim with fake account information without triggering any security warnings in the web browser, since the connection appears to be legitimate and encrypted.

Recently, a new variant of Dyre was detected that includes the ability to access Microsoft 's Outlook e-mail client in order to spread the Upatre malware , which then funnels the Dyre Trojan to victims' computers.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS