HomeSecurityNew online banking malware causes problems in Japan

New online banking malware causes problems in Japan

A new online banking malware, discovered in Operation Emmental, has caused problems in Japan. TROJ_WERDLOD, a new malware detected, has been causing problems in the country since December 2014. More than 400 systems were affected by the new malware.

New online banking malware causes problems in Japan
According to Hitomi Kimura, a security specialist at TrendMicro, the malware can change two settings that allow information theft at the network level.

It does not require a reboot or any memory-resident processes on the affected systems.

Kimura wrote in a blog post that one of the settings is modified by the system's proxy settings. Attackers control the path from Internet traffic to the proxy. And the second setting is the additional malicious root certificate in the system's trusted root store. It allows malicious site certificates, which are added in man-in-the-middle attacks, to be used without triggering alerts or error messages.

He wrote that TROJ_WERDLOD affects users via spam mails which contain an attached .RTF document. The document is said to be an invoice or a receipt from some online shopping site. If the user opens the .RTF file, they are prompted to double-click the document icon in order for TROJ_WERDLOD to execute on the system.

werdlod1b
The spam mail that leads to TROJ_WERDLOD

 

According to Kimura, the hackers used a fake certificate and proxy in Operation Emmental. They also used fake mobile apps to steal SMS messages from online banks. It seems that the same behavior may be seen again in Japan in the future, since Japanese banks rarely use SMS authentication.

 

Kimura suggests, in order to restore an infected PC, the following measures should be taken:

[signoff icon=”icon-pin”]1. Remove the automatic proxy setting (proxy automatic setting) on Windows and Firefox

2. Remove the malicious root certificate that was installed by TROJ_WERDLOD and stored on Windows and Firefox. This malicious root certificate has the following signature:

A134D31B 881A6C20 02308473325950EE 928B34CD[/signoff]

 

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS