A new online banking malware, discovered in Operation Emmental, has caused problems in Japan. TROJ_WERDLOD, a new malware detected, has been causing problems in the country since December 2014. More than 400 systems were affected by the new malware.

According to Hitomi Kimura, a security specialist at TrendMicro, the malware can change two settings that allow information theft at the network level.
It does not require a reboot or any memory-resident processes on the affected systems.
Kimura wrote in a blog post that one of the settings is modified by the system's proxy settings. Attackers control the path from Internet traffic to the proxy. And the second setting is the additional malicious root certificate in the system's trusted root store. It allows malicious site certificates, which are added in man-in-the-middle attacks, to be used without triggering alerts or error messages.
He wrote that TROJ_WERDLOD affects users via spam mails which contain an attached .RTF document. The document is said to be an invoice or a receipt from some online shopping site. If the user opens the .RTF file, they are prompted to double-click the document icon in order for TROJ_WERDLOD to execute on the system.

According to Kimura, the hackers used a fake certificate and proxy in Operation Emmental. They also used fake mobile apps to steal SMS messages from online banks. It seems that the same behavior may be seen again in Japan in the future, since Japanese banks rarely use SMS authentication.
Kimura suggests, in order to restore an infected PC, the following measures should be taken:
[signoff icon=”icon-pin”]1. Remove the automatic proxy setting (proxy automatic setting) on Windows and Firefox
2. Remove the malicious root certificate that was installed by TROJ_WERDLOD and stored on Windows and Firefox. This malicious root certificate has the following signature:
A134D31B 881A6C20 02308473325950EE 928B34CD[/signoff]
