Skip to main content

Shylock banking malware can detect remote desktops

posted onNovember 29, 2012
by l33tdawg

Shylock, a trojan dropper that steals bank account information, is employing a new trick to avoid detection: hiding from researchers who may be studying it via remote desktop connections.

Initially discovered in February 2011 by security firm Trusteer, Shylock delivers web injects into victims' browsers and logs keystrokes.The malware is concealed in endpoint device memory files and rewrites Windows processes. Shylock, named after the ruthless money lender in Shakespeare's The Merchant of Venice, also deletes its installation files, runs solely in memory, and begins the process again once the infected machine reboots.

George Tubin, senior security strategist at Trusteer, told SCMagazine.com on Wednesday that Shylock appears to be a widespread threat largely undiscovered by victims, as it sits idly on their computers until they visit targeted banking sites. Victims mostly are customers of  U.S. and European financial institutions, he said, and the attacks are often initiated by phishing emails or drive-by downloads.

Source

Tags

Viruses & Malware

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th