Page 1 of 3 123 LastLast
Results 1 to 10 of 22
Like Tree1Likes

Thread: New Banking Trojan Targets All Major Browsers.

  1. #1
    Guest
    Overall activity: 54.0%

    Join Date
    May 2007
    Location
    Philippines
    Posts
    4,006
    Liked
    710 times
    Points
    47,645

    Angry New Banking Trojan Targets All Major Browsers.

    Dubbed Tatanga, the trojan is written in C++ and is organized in modules with different functionality which are decrypted in memory as needed.

    Like other banking trojans, Tatanga executes Man-in-the-Browser (MitB) attacks in order to perform unauthorized transactions from the accounts of its victims
    Tatanga hooks into explorer.exe and can inject HTML in Internet Explorer, Mozilla Firefox, Google Chrome, Opera, Minefield (Firefox dev builds), Maxthoon, Netscape, Safari and Konqueror, basically every popular browser.

    Other noteworthy features include support for 64-bit Windows, anti-VM technology, mobile OTP phishing and Trusteer Rapport evasion.
    Multi-browser based trojan... All-in one package!

    Sources:

    Last edited by Ceyfer √; 02-28-2011 at 08:44 AM. Reason: link fixed
    "Stars and the Sun"


  2. #2
    Administrator
    Overall activity: 62.0%

    Join Date
    Nov 2006
    Location
    Malaysia
    Posts
    9,804
    Liked
    1656 times
    Points
    48,752
    First of all, made in C++ so that it runs on all Windows without dependencies.
    Seems like the person who made this Trojan knows what he is doing.

  3. #3
    Guest
    Overall activity: 54.0%

    Join Date
    May 2007
    Location
    Philippines
    Posts
    4,006
    Liked
    710 times
    Points
    47,645
    Quote Originally Posted by Raymond View Post
    First of all, made in C++ so that it runs on all Windows without dependencies.
    Yeah. In fact, the author just updated the malware just days ago. Seems like it going to support more browsers and able to adapt & adjust quickly against the odds.

  4. #4
    ted
    ted is offline
    Star
    Overall activity: 99.7%

    Join Date
    Apr 2009
    Location
    LIVERPOOL UK
    Posts
    1,128
    Liked
    527 times
    Points
    10,630
    one of the many reasons i dodge online banking
    Once you've got past my charm, good looks, intelligence and my sense of humour,
    I think it's my modesty that stands out.

  5. #5
    Malware Hunter
    Overall activity: 0%

    Join Date
    Sep 2009
    Location
    Kolkata, India
    Posts
    485
    Liked
    104 times
    Points
    6,801
    Safety measures of course could be using a good anti-malware and a good anti-logger. Also, one should use virtual keyboards, etc. for online banking to decrease chances of being scammed.

  6. #6
    The Specialist *
    Overall activity: 76.0%

    Join Date
    May 2010
    Location
    KOLKATA
    Posts
    5,162
    Liked
    731 times
    Points
    47,580
    Great news . Thanks for the heads up . Now we can expect something more from the author .
    I don't need to know everything, I just need to know where to find it, when I need it.

  7. #7
    Whiz Kid
    Overall activity: 0%

    Join Date
    Sep 2008
    Location
    Albania
    Posts
    1,771
    Liked
    80 times
    Points
    20,857
    Quote Originally Posted by ceyfer View Post
    Yeah. In fact, the author just updated the malware just days ago. Seems like it going to support more browsers and able to adapt & adjust quickly against the odds.
    Is it in beta stage or it's stable release? :P

    Screw Google! Ask me!


  8. #8
    I'd rather be fishing!
    Overall activity: 0%

    Join Date
    Jan 2011
    Location
    Minnesota, USA
    Posts
    3,155
    Liked
    1543 times
    Points
    4,220
    Thanks for the read ceyfer! Something else to keep an eye out for. I just wish these people would put their talents to better use.
    Life isn't about waiting for the storm to pass, it's about learning to dance in the rain!

  9. #9
    Experienced User
    Overall activity: 25.0%

    Join Date
    Jun 2009
    Location
    Quarantine
    Posts
    1,829
    Liked
    74 times
    Points
    21,711
    All-in one package <---Good deal.

    ---------- Post added at 08:58 PM ---------- Previous post was at 08:50 PM ----------

    According to this screenshot:
    http://3.bp.blogspot.com/-vZnxtNAPCoI/TWezKeI0LMI/AAAAAAAAAss/KWP43XMLVo4/s1600/demo.png
    It will make the user doing a "demo transfer"? Or it does all by itself without asking?
    This user has not enabled signature viewing, if you wish to view this user's signature please upgrade to a Raymond Gold account. THIS PORTION OF THIS QUOTE HAS BEEN CENSORED BY SOPA.

  10. #10
    Experienced User
    Overall activity: 0%

    Join Date
    May 2010
    Posts
    3,271
    Liked
    155 times
    Points
    6,541
    Thanks ceyfer for read It seems that MitB attacks will arise due to greater scope (C++, browser independent, x64 compatibility, Trusteer Rapport evasion, etc.). Secure OS (e.g., live boot CD) will be better alternative for banking now.
    Windows 7 SP1 Ultimate x86 + KIS 2011 (11.0.2.556 b.a.c.d) + Sandboxie Paid (3.54) + Deep Freeze Standard (7.20.020.3398)

 

 
Page 1 of 3 123 LastLast

Similar Threads

  1. SpyEye Targets Opera, Google Chrome Users
    By leofelix in forum Spyware/Viruses
    Replies: 7
    Last Post: 04-28-2011, 07:13 AM
  2. Polymorphic Injection Attack Targets WordPress Blogs
    By Alboguy in forum Spyware/Viruses
    Replies: 2
    Last Post: 12-02-2010, 03:13 PM
  3. Stuxnet Worm Attacks Industrial Targets
    By Alboguy in forum Spyware/Viruses
    Replies: 2
    Last Post: 09-25-2010, 01:17 AM
  4. Looking at a banking Trojan right now.
    By Gabethebabe in forum Spyware/Viruses
    Replies: 17
    Last Post: 01-22-2010, 06:37 PM
  5. Trojan virus steals banking info
    By Mark in forum Spyware/Viruses
    Replies: 3
    Last Post: 11-07-2008, 10:56 PM

Tags for this Thread

All times are GMT +8. The time now is 09:44 AM.