Author Topic: Russian (Gozi) Trojan powering massive ID-theft ring  (Read 3666 times)

0 Members and 1 Guest are viewing this topic.

CharleyO

  • Guest
Russian (Gozi) Trojan powering massive ID-theft ring
« on: March 22, 2007, 07:05:07 PM »
***

"Researchers at SecureWorks have stumbled upon what appears to be a massive identity theft ring using state-of-the-art Trojan code to steal confidential data from thousands of infected machines in the U.S."

http://blogs.zdnet.com/security/?p=133&tag=nl.e622


***

guruh

  • Guest
Re: Russian (Gozi) Trojan powering massive ID-theft ring
« Reply #1 on: March 22, 2007, 11:31:58 PM »
Quote
http://www.secureworks.com/research/threats/gozi/

Highlights

A single attack by a single variant compromises more than 5200 hosts and 10,000 user accounts on hundreds of sites.

    * Steals SSL data using advanced Winsock2 functionality
    * State-of-the-art, modularized trojan code
    * Spread through IE browser exploits
    * Undetected for weeks, months by many AV vendors
    * Customized server/database code to collect sensitive data
    * Customer interface for on-line purchases of stolen data
    * Accounts compromised by stealing data primarily from infected home PCs
    * Accounts at top financial, retail, health care, and government services affected
    * Data's black market value at least $2 million

There are two other known variants. New variants, similar attacks inevitable.

Firefox is safer?

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48839
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Russian (Gozi) Trojan powering massive ID-theft ring
« Reply #2 on: March 22, 2007, 11:52:29 PM »
It isn't browser dependent so in this case, no.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Re: Russian (Gozi) Trojan powering massive ID-theft ring
« Reply #3 on: March 23, 2007, 10:50:12 AM »
Hi bob3160,

From the description in the link: "Launch attacks through Internet Explorer browser exploits". How can you then say, it is browser independent? With NoScript installed, and checking my links with the DrWeb add-on I know I can prevent many a trojan downloaders to run. I agree with you that Mozilla type browsers can infect because the OS is "explorer"-dependant so not immediate but through a vulnerable explorer. Here with Gozi again the malware vector, and it is the vector by choice,  is JAVASCRIPT. Read about the way it infects, and how it was detected here:
http://www.secureworks.com/research/threats/gozi/?threat=gozi
So with IE you are vulnerable, with IE with javascript disabled you are not vulnerable, but then you loose out on interactivity. The malware crooks know that most browser users like to use their browsers as default and like to click along with full operability, so their victims are just sitting out there for them like sitting ducks.
It is not the browser but the ill-equiped user that is the weakest part of the vulnerability chain,

polonus

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89687
  • No support PMs thanks
Re: Russian (Gozi) Trojan powering massive ID-theft ring
« Reply #4 on: March 23, 2007, 01:49:54 PM »
There is also mention that it uses ActiveX, that and the "Launch attacks through Internet Explorer browser exploits" would lead me to believe it is browser specific.

Quote
The page included in this last IFRAME contained JavaScript code using XMLHTTP and ADODB (ActiveX Data Objects) functions to download and run an EXE file which was hosted on the same server.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48839
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Russian (Gozi) Trojan powering massive ID-theft ring
« Reply #5 on: March 23, 2007, 02:40:42 PM »
 :o :-[ :-X
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet