New Trojan Stealing Online Banking Data, Warns CERT-In

Advertisement
By Press Trust of India | Updated: 5 November 2014 17:32 IST
Cyber-security sleuths have alerted online banking customers in the country against the malicious activity of a deadly Trojan which steals classified data and passwords of a vulnerable user.

"It has been reported that variants of a new banking Trojan dubbed as 'Dyreza' are spreading. The malware mainly targets the customers of well-known financial institutions running Microsoft Windows operating system."

"It propagates by using social engineering techniques or by means of spam messages pretending to be genuine mail received from financial institution containing either a zip or pdf as an email attachment exploiting the vulnerability in unpatched versions of Adobe Reader to download the malware."

"The zip contains a self executing malware which installs itself on the target system on being extracted," the Computer Emergency Response Team of India (CERT-In) said in its latest advisory to users of online banking system.

Advertisement

The CERT-In is the nodal agency to combat hacking, phishing and to fortify security-related defences of the Indian Internet domain.

Advertisement

The agency said the malware is capable to wreak havoc into a secure system in a number of ways. The Trojan, an unauthorised programme which passively gains control over another system by representing itself as an authorised programme, steals infected bank customers' online banking credentials, can bypass secure protection settings using browser hijacking, can capture keystrokes, perform man-in-the-middle attack to intercept network traffic and communicate with command and control server, the agency said.

Once the spam mail is received by a bank customer, the agency said, it 'entices' the user to download and extract the zip file which then begins its destructive and stealing action.

Advertisement

The Trojan is categorised as 'deadly' as it can acquire as many as ten aliases to evade anti-virus updates.

The said malware performs by injecting malicious code in the web browsers including Chrome, Firefox, Internet Explorer, so that when infected user visits any of the banking sites their credentials are stolen.

Advertisement

The command traffic, after the Trojan is activated in the user network, is first redirected to the malicious server and then to the legitimate banking site thereby copying and stealing proprietary data, the advisory said.

The CERT-In has suggested some counter-measures to safeguard against this Trojan.

"Configure your email server to block or remove email that contains file attachments that are commonly used to spread threats such as vbs, bat, exe, pif and scr files, set Internet and local intranet security zone settings to high, lock out accounts after number of incorrect login attempts."

"Also, limit or eliminate the use of shared or group accounts, do not visit untrusted websites, enable firewall at gateway or desktop level, do not download or open attachment in emails received from untrusted sources or unexpectedly received from trusted users and install and scan anti-malware engines and keep them up-to-date," it said.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Cyber Attack, Hacking, Internet, Trojan, malware
Advertisement

Related Stories

Popular Mobile Brands
  1. Redmi 15C 5G Chipset Details Leaked, Could Launch in India at This Price
  2. Xiaomi 17 and Xiaomi 17 Pro First Impressions
  3. OnePlus Ace 6T Launch Timeline Revealed; Will Sport This Snapdragon Chip
  4. Here's When the Nothing Phone 3a Lite Will Launch in India
  5. Poco F8 Series Will Be Launched Globally on This Date
  6. Vivo X300 and Teleconverter Kit India Prices Tipped Ahead of Launch
  7. Raktabeej 2 Arrives on OTT Platforms This November: All You Need to Know
  8. Oppo Find X9 Series Price in India Leaked Again Ahead of Debut
  9. Samsung Galaxy Buds 4 Pro Leak Hints at New Design, Head Gestures Support
  10. Black Ops 7 Faces Backlash Over Alleged GenAI Use for In-Game Artwork
  1. Bison Kaalamaadan OTT Release Date Confirmed: When and Where to Watch This Tamil Sports Action Drama Online?
  2. Samsung Galaxy Z TriFold Testing Commences in the US Ahead of Imminent Launch: Report
  3. Steak ‘n Shake Expands to El Salvador as Bitcoin Strategy Gains Momentum
  4. Samsung Galaxy Buds 4 Pro Leak Hints at Refreshed Design, Head Gestures Feature
  5. Redmi 15C 5G Price in India, Key Specifications Leaked Ahead of Launch: Here’s How Much it Might Cost
  6. India Begins AI Adoption: 47 Percent of Enterprises Use AI for Multiple Use Cases, Says EY
  7. Nothing Phone 3a Lite India Launch Date Confirmed: Expected Specifications, Features
  8. Call of Duty: Black Ops 7 Draws Flak Over Alleged GenAI Use as Steam Player Count Underwhelms
  9. Apple Ordered to Pay Masimo $634 Million in Apple Watch Patent Dispute
  10. OnePlus Ace 6T Launch Timeline Confirmed; Will Debut This Month With Snapdragon 8 Gen 5 SoC
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.