Security Software Zone Security Software Zone
Home Contact Us
Search in
Forum SecurityToolbox Submit Software
Security Software Zone Login
Security Software Categories
News - Articles - Reviews
Free Newsletter
Join our mailing list and receive
security software news and
advice from our experts.
Submit
  Security Software Zone » Software Reviews » Virus Protection » New Trojan Undetected for More Than 50 Days!

New Trojan Undetected for More Than 50 Days!

Category: Virus Protection
Published: 03/27/2007, 18:14  
Editor: Remus Zoica
 
Print article
Send to a friend
Search in reviews
Looks like a Russian Trojan program named Gozi remained undetected for more than 50 days. In this time the trojan aquired confidential data worth $2 million on the black market. Among the stolen data there were more than 10,000 private records belonging to about 5,200 US users, about 2,000 Social Security numbers, as well as account numbers, user names and passwords for bank accounts and e-commerce sites. It also included employee passwords for applications belonging to more than 300 companies and government organisations - including several law enforcement agencies in the US - and medical information of health care employees and patients whose user names and passwords were stolen from their home PCs.

The stolen information was sent by Gozi to a server in St. Petersburg, where it was then sold on a subscription basis to an unknown number of individuals. The value of the stolen data is estimated to be around: $2 million. Don Jackson, a security researcher at SecureWorks, uncovered the theft in January. Jackson said that there are at least two more known variants of Gozi, meaning there are new attacks taking place. According to Jackson, an acquaintance reported that several accounts on websites he visited from work and home had been hijacked. An investigation of his friend's PC uncovered a previously unclassified malware executable that appeared to have been installed last December.

The Trojan was designed to steal data from encrypted SSL streams and send it to a server in Russia. It took advantage of a vulnerability in the iFrame tags of Internet Explorer - the buffer overflow attack basically allows attackers to take complete control of a compromised system. Jackson said that the server to which the information was being sent had a very professional-looking front end that allowed users to log into individual accounts, view indexed data and query fields such as URL and form parameters. Each query had a price, Jackson said. The currency used on the site was WMZ, a WebMoney unit the value almost the same as the US dollar.

When The Trojan was discovered, in January, not one of the 30 anti-virus programs he tested recognised it. Some of the programs flagged it as a suspicious file or a generic threat based on the fact that it was using a commonly known packing tool to compress the code. After a month, the new updated versions of the same programs were tested again and most of them did a better job of finding Gozi, but five of the them completely missed it.

Details about Trojan and the information on the Russian server have been passed on to law enforcement authorities, and to several of the affected companies. The subscription service is not working, but the server housing the data is still online and is continuing to receive stolen information.

Bookmark to:
Add 'New Trojan Undetected for More Than 50 Days!' to Del.icio.us Add 'New Trojan Undetected for More Than 50 Days!' to digg Add 'New Trojan Undetected for More Than 50 Days!' to FURL Add 'New Trojan Undetected for More Than 50 Days!' to reddit Add 'New Trojan Undetected for More Than 50 Days!' to Technorati Add 'New Trojan Undetected for More Than 50 Days!' to Yahoo My Web Add 'New Trojan Undetected for More Than 50 Days!' to Stumble Upon Add 'New Trojan Undetected for More Than 50 Days!' to Google Bookmarks Add 'New Trojan Undetected for More Than 50 Days!' to RawSugar Add 'New Trojan Undetected for More Than 50 Days!' to Squidoo Add 'New Trojan Undetected for More Than 50 Days!' to Spurl Add 'New Trojan Undetected for More Than 50 Days!' to Netvouz Add 'New Trojan Undetected for More Than 50 Days!' to Rojo Add 'New Trojan Undetected for More Than 50 Days!' to Bloglines Add 'New Trojan Undetected for More Than 50 Days!' to Tailrank
Add comment
Security Software Zone is not responsible for the content of these User comments. The views and opinions expressed are those of the individual poster and not the Security Software Zone.
User comments (0):

There is no comment for this review.

 
Reviews related to New Trojan Undetected for More Than 50 Days!
 

New Online Web-Site: Dr.Web AV-Desk
  Doctor Web, Ltd. has got another URL – www.av-desk.com. The first Internet-service of the company - Dr.Web AV-DeskTM- has got its own web-site.
Read More >
02/21/2008, 19:20
 

BluePrint Data Helps Fighting the Online Shadow Threat
 To help fight online crime, BluePrint Data announced today that it is making its Internet Web / URL Filtering database and technologies available to Antivirus, Antispyware, and Antimalware solution providers.
Read More >
05/16/2008, 11:12
 

Feature-Packed Anti-Virus Protection Launched by Agnitum
 The leading firewall provider, Agnitum, announced today the availability of Outpost Antivirus Pro, offering an extended security arsenal to protect users against identity theft, malware infection, and websites that may be hosting malicious content. The company, in a new twist, is offering Outpost Antivirus Pro at a flat annual subscription fee rather than the license-plus-annual renewals model that has become the industry standard.
Read More >
03/18/2008, 14:10
 

Delete trojan horse virus - What is a trojan horse?
 The Trojan Horse Virus for your PC is something that is evil and bad concealed within something that seems good and positive
Read More >
12/07/2006, 17:35
 

PC Viruses
 Owning a PC is a relatively large responsibility, especially when one observes the amount of maintenance and cleaning involved in keeping your system in as best a condition as possible.
Read More >
01/09/2007, 08:20

Sponsored