Security Software Zone Security Software Zone
Home Contact Us
Search in
Forum SecurityToolbox Submit Software
Security Software Zone Login
Security Software Categories
News - Articles - Reviews
Free Newsletter
Join our mailing list and receive
security software news and
advice from our experts.
Submit
  Security Software Zone » Software Reviews » Virus Protection » New Trojan Undetected for More Than 50 Days!

New Trojan Undetected for More Than 50 Days!

Category: Virus Protection
Published: 03/27/2007, 18:14  
Editor: Remus Zoica
 
Print article
Send to a friend
Search in reviews
Looks like a Russian Trojan program named Gozi remained undetected for more than 50 days. In this time the trojan aquired confidential data worth $2 million on the black market. Among the stolen data there were more than 10,000 private records belonging to about 5,200 US users, about 2,000 Social Security numbers, as well as account numbers, user names and passwords for bank accounts and e-commerce sites. It also included employee passwords for applications belonging to more than 300 companies and government organisations - including several law enforcement agencies in the US - and medical information of health care employees and patients whose user names and passwords were stolen from their home PCs.

The stolen information was sent by Gozi to a server in St. Petersburg, where it was then sold on a subscription basis to an unknown number of individuals. The value of the stolen data is estimated to be around: $2 million. Don Jackson, a security researcher at SecureWorks, uncovered the theft in January. Jackson said that there are at least two more known variants of Gozi, meaning there are new attacks taking place. According to Jackson, an acquaintance reported that several accounts on websites he visited from work and home had been hijacked. An investigation of his friend's PC uncovered a previously unclassified malware executable that appeared to have been installed last December.

The Trojan was designed to steal data from encrypted SSL streams and send it to a server in Russia. It took advantage of a vulnerability in the iFrame tags of Internet Explorer - the buffer overflow attack basically allows attackers to take complete control of a compromised system. Jackson said that the server to which the information was being sent had a very professional-looking front end that allowed users to log into individual accounts, view indexed data and query fields such as URL and form parameters. Each query had a price, Jackson said. The currency used on the site was WMZ, a WebMoney unit the value almost the same as the US dollar.

When The Trojan was discovered, in January, not one of the 30 anti-virus programs he tested recognised it. Some of the programs flagged it as a suspicious file or a generic threat based on the fact that it was using a commonly known packing tool to compress the code. After a month, the new updated versions of the same programs were tested again and most of them did a better job of finding Gozi, but five of the them completely missed it.

Details about Trojan and the information on the Russian server have been passed on to law enforcement authorities, and to several of the affected companies. The subscription service is not working, but the server housing the data is still online and is continuing to receive stolen information.

Bookmark to:
Add 'New Trojan Undetected for More Than 50 Days!' to Del.icio.us Add 'New Trojan Undetected for More Than 50 Days!' to digg Add 'New Trojan Undetected for More Than 50 Days!' to FURL Add 'New Trojan Undetected for More Than 50 Days!' to reddit Add 'New Trojan Undetected for More Than 50 Days!' to Technorati Add 'New Trojan Undetected for More Than 50 Days!' to Yahoo My Web Add 'New Trojan Undetected for More Than 50 Days!' to Stumble Upon Add 'New Trojan Undetected for More Than 50 Days!' to Google Bookmarks Add 'New Trojan Undetected for More Than 50 Days!' to RawSugar Add 'New Trojan Undetected for More Than 50 Days!' to Squidoo Add 'New Trojan Undetected for More Than 50 Days!' to Spurl Add 'New Trojan Undetected for More Than 50 Days!' to Netvouz Add 'New Trojan Undetected for More Than 50 Days!' to Rojo Add 'New Trojan Undetected for More Than 50 Days!' to Bloglines Add 'New Trojan Undetected for More Than 50 Days!' to Tailrank
Add comment
Security Software Zone is not responsible for the content of these User comments. The views and opinions expressed are those of the individual poster and not the Security Software Zone.
User comments (0):

There is no comment for this review.

 
Reviews related to New Trojan Undetected for More Than 50 Days!
 

W32.Rinbot Worm Virus Removal – Security answers from Symantec
 The first signs of W32.Rinbot.L were seen in-the-wild on February 28, 2007. This worm spreads by attempting to access network file shares and SQL servers that may have weak passwords.
Read More >
03/05/2007, 22:40
 

Free Antivirus Protection Offered by PROMT to its Customers
 A leading developer of machine translation products and services, PROMT, is pleased to announce it is offering new purchasers a free 180-day license for Agnitum's award-winning Outpost AntiVirus Pro, an offer which applies to customers worldwide who purchase PROMT automated translation software with multilingual support at the company's PROMT Automated Translation Software E-store.
Read More >
05/27/2008, 11:26
 

Free Web Your Way Memberships Distributed by Thasay
 Thasay Computer and Marketing has announced acceptance as a distribution partner of the Web Your Way membership. Providing a host of free services to the benefit of all Internet users, the Web Your Way is a completely free online membership.
Read More >
04/03/2008, 09:50
 

Norton Internet Security 2008 And Norton Antivirus 2008, Industry Leading Security Solutions That Have Been Enhanced!
 
Read More >
09/03/2007, 21:56
 

AAAntivirus leading supplier of anti-virus and anti-malware solutions
 AAAntivirus Achieves Kaspersky Lab's 'Partner of the Year' Award AAAntivirus recognized for innovation and leadership in delivering antivirus and antimalware solutions in partnership with Kaspersky Lab.
Read More >
01/09/2007, 09:39

Sponsored