HomeSecurityBanking Trojan exploited in 2nd cyber attack on Bundestag

Banking Trojan exploited in 2nd cyber attack on Bundestag

Banking Trojan exploited in 2nd cyber attack on Bundestag – Experts from security firm GData have discovered a second stage of the cyber attack on the German Parliament (Bundestag) that exploited a banking trojan to steal data.

Banking Trojan exploited in 2nd cyber attack on Bundestag

In recent weeks, much has been said and various opinions have been published about the cyberattack against the Bundestag, as well as a view that Russian state-backed hackers are likely involved. Media outlets have reported that the hackers used sophisticated malware, which is very difficult to remove from more than 20,000 computers belonging to the German Parliament.

Security experts at security firm GData have identified a second round of cyberattacks on the German Bundestag parliament, in which attackers used a variant of the Swatbanker online banking trojan.

Swatbanker is a data stealer malware that collects various types of data from the infected machine, including data entered by users in forms as well as a list of the last websites visited by victims.

Researchers discovered that the operators behind the Swatbanker botnet have implemented new filtering features for the domain "Bundestag.btg", which is the address of the German Parliament's intranet, between June 8 and 10, 2015.

"It is currently unclear whether this is a new motivated attack or a continuation of the attacks that came to light in late May 2015. G DATA's analyses indicate that new variants of the online banking Trojan Swatbanker have been used," GDATA said in a blog post.

Experts have no evidence to prove that this new wave of attacks is linked to the previous one or that it is being led by a specific group.

"According to initial analyses, we can assume that this is a criminally motivated attack. However, it should also be noted that it may be an extension of an existing attack that is simply disguised as an 'eCrime' copycat," said Mr. Ralf Benzmüller, Head of G DATA Security Labs.

“Such data can then be used to attack the relevant server directly,” Mr. Benzmüller added in his statement.

GData has published a technical report reporting on the latest discovery related to the attacks on the German Federal Parliament (Bundestag).

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS