The Vawtrak banking Trojanis back, with the ability to steal credentials and sensitive information from customers of hundreds of banking and financial institutions.

The latest version, according to Heimdal Security, is capable of capturing video and images and launching man-in-the-middle .
More than 15 financial institutions in Canada are being targeted by a web-injection campaign similar to that used by the Zeus malware family, which allows the cybercriminal to bypass two-factor security.
So far, it has hit about 15,000 machines in Canada.
Vawtrak as Neverquest) is delivered via drive-by downloads on unsecured websites or by injecting malicious code into legitimate websites, but is also spread through phishing campaigns on social media and via spam. This is where a MiTM attack is launched, allowing hackers to intercept unencrypted web traffic while victims believe they are on a secure connection. The victim then believes that the credentials are being sent to a legitimate bank, but the malware actually redirects the traffic to a compromised server, using encryption to hide the transmission.
The command and control center of the attack appears to be located in Russia.
Unfortunately, once the malware is installed on a system, it poses several issues when it comes to recovery. “To complicate a potential detection or removal process, cybercriminals use the recovered credentials to log in to bank accounts via virtual desktop networks, which are shared desktop systems that allow remote control of the victim’s computer,” Heimdal said in a blog post. “Since the request to log in to the online banking account originates from the victim’s computer, it is almost impossible for the bank account to detect the cyberattack in progress.”
To avoid the risk of infection, users should maintain operating systems and use up-to-date software with the latest security patches, because Vawtrak can be spread via exploit kits. And of course, users should not click on links or download attachments from emails received from unknown sources.
“Vawtrak is one of the most dangerous financial information-stealing malware recently identified by our security experts,” said Heimdal.
