GozNym banking malware spotted now in Europe

frogboy

In memoriam 1961-2018
Thread author
Verified
Top Poster
Well-known
Jun 9, 2013
6,720
IBM's X-Force reported today the actors behind the hybrid GozNym banking trojan have released a new configuration that is targeting European banks with the new angle of using redirection attacks.

The recent targets include 17 Polish banks and one in Portugal. However, a new twist has been included, using redirection attacks targeted at customers using these banking insititutions. IBM reported the GozNym gang have created about 200 URLs that point a victim to what they believe is their bank website, but in fact it is one controlled by the bad guys.

“By keeping the victim away from the bank's site, the fraudster can deceive them into divulging critical authentication codes on the replica site, all without the bank knowing that the customer's session has been compromised,” said Limor Kessem, executive security advisor at IBM.

Kessem believes the Dridex gang is behind the GozNym attacks as it is the only cybergang known to use redirection attacks, although, she added, rumors have the Neverquest organization also implementing redirection attacks.

Full Articl. GozNym banking malware spotted now in Europe
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top