Security researchers at Fortinet have uncovered a new strain of the banking trojan, Vawtrak, which implements an obfuscation mechanism based on the Tor2Web service.
According to researchers, the developers of the banking Trojan Vawtrak are now adopting a new tactic to hide the web traffic of its servers, utilizing the Tor2Web service to cover up malicious connections.
Previously, the actors behind the malware (also known as Neverquest) exploited the steganography to evade detection, while some strains of the malware were spread using Microsoft.
In February 2015, security experts discovered variants of Vawtrak that exploited Windows PowerShell, combined with the use of macros, to enhance its effectiveness. Now, Fortinet researchers have discovered an advanced variant of the banking trojan that hides its C&C servers on the Tor anonymity network (via the Tor2Web service), making it harder to crack down on criminal activity.
[alert variation=”alert-info”]The Tor2Web service allows users to access Tor resources without using the classic Tor client, but using a common browser.[/alert]
Researchers explain that Vawtrak uses a sophisticated Domain Name Generator that allows the malware to communicate with C&C servers, generating a series of domain names that it connects to in order to receive commands.
Vawtrak also carries advanced data theft and web-injection capabilities, while it has multiple protection mechanisms (such as disabling antivirus solutions) to avoid detection and analysis.
Initially, the trojan was used by cybercriminals to intercept all kinds of information and record victims' activities (monitoring keystrokes - taking screenshots/video), but later its creators adapted it to target banks, financial institutions, and retail businesses.

