Dyre Trojan Uses its own SSL certificate

Its developers Dyre Trojan seems to have improved its functionality. Dyre is a banking Trojan, which now has its own SSL certificate to communicate with the command and control center (C&C).
Σε μια πρόσφατη ανάλυση ενός δείγματος, ερευνητές ασφαλείας της , ανακάλυψαν ότι το κακόβουλο λογισμικό χρησιμοποιεί ένα ψηφιακό πιστοποιητικό που εκδίδεται από την Internet Widgits Pty Ltd. Η επικοινωνία με τους απομακρυσμένους διακομιστές γίνεται από τις θύρες 443 και 4443.Troy Dyre Trojan Dyre Trojan

By using their own communication certificate, the new Dyre variant makes it much harder for security solutions to recognize the traffic as malicious.
The new version of Dyre steals browser data and lists installed programs on of the victim.
In the latest variant, there is also a feature called “browsersnapshot.” The new feature is responsible for collecting browser data such as cookies, client-side certificates, and Windows private keys from the certificate store used by the , but also in its certificate database Firefox.

It also lists all installed computer programs as well as operating services. This is done to create more effective attacks.

As for the commands and targets, the Trojan downloads them from the C & C server. This makes the malware a very flexible into the hands of cybercriminals as they can add or remove targets and commands as per their needs.

For the record, the malware has been specifically created to steal users' banking information and was originally targeted from Bank of America, Citigroup, Royal Bank of Scotland, Ulsterbank and Natwest.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).