New Banking Trojan Targets All Major Browsers

Status
Not open for further replies.

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
Spanish security firm S21sec has identified a new banking trojan capable of injecting HTML into all popular browsers which uses a rootkit to hide its components.

Dubbed Tatanga, the trojan is written in C++ and is organized in modules with different functionality which are decrypted in memory as needed.

Like other banking trojans, Tatanga executes Man-in-the-Browser (MitB) attacks in order to perform unauthorized transactions from the accounts of its victims.

The trojan currently targets banks from Western European countries, particularly the United Kingdom, Germany, Spain and Portugal.

It currently has a very low detection rate. A signature-based Virus Total scan reveals that only 9 in 43 antivirus engines currently detect the infector as malicious and most of them do it under generic names.

Microsoft calls it Trojan:Win32/Mariofev.B and has first added detection for it on September 03, 2010. However, the definition was updated a week ago, probably to account for new variants.

More details - link
 

LaserWraith

Level 1
Feb 24, 2011
497
Hmm...Comodo got it. Anyway, can this just happen when you visit a site, or do you have to download and run some executable?
 

LoftedAphid86

New Member
Feb 24, 2011
1,107
LaserWraith said:
Hmm...Comodo got it. Anyway, can this just happen when you visit a site, or do you have to download and run some executable?
Considering it says 'injection', I would think that it would mean an exploit, which would mean just visiting a site.
 

LaserWraith

Level 1
Feb 24, 2011
497
elliotcroft said:
Considering it says 'injection', I would think that it would mean an exploit, which would mean just visiting a site.

An executable could just as well "inject" something into the browser to monitor/mess up things.

Although I'm not an expert. :p
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top