Security Alert: GootKit and Godzilla Infostealers Target Victims’ Financial Information

Andra Zaharia

From Heimdal
Thread author
Verified
Jun 29, 2015
104
Two fresh campaigns are currently spreading GootKit and Godzilla Loader, targeting both financial institutions and Internet banking users worldwide.

Are cyber criminals trying to remind us that ransomware is not the only financial malware on the market?
 

Vasudev

Level 33
Verified
Nov 8, 2014
2,247
Two fresh campaigns are currently spreading GootKit and Godzilla Loader, targeting both financial institutions and Internet banking users worldwide.

Are cyber criminals trying to remind us that ransomware is not the only financial malware on the market?
@Andra Zaharia: Any list of victims and how to identify if the banking site has been infected from end-user's POV?
 
  • Like
Reactions: Svoll and DardiM

Andra Zaharia

From Heimdal
Thread author
Verified
Jun 29, 2015
104
@Andra Zaharia: Any list of victims and how to identify if the banking site has been infected from end-user's POV?

Thanks for the great question!

The campaigns are currently ongoing and under investigation, so I can't share any list of victims.

In terms of infection, the infostealers check the URLs in the user's browser to see when the user accesses online banking services. It then works to intercept traffic between the user and the online banking portal.

Also, they can download keyloggers, capture screenshots and they periodically connect to their C&Cs to upload the harvested data.

Once I have more details, I will most definitely add them to the alert. Thanks for your patience!
 

Vasudev

Level 33
Verified
Nov 8, 2014
2,247
The campaigns are currently ongoing and under investigation, so I can't share any list of victims.

In terms of infection, the infostealers check the URLs in the user's browser to see when the user accesses online banking services. It then works to intercept traffic between the user and the online banking portal.

Also, they can download keyloggers, capture screenshots and they periodically connect to their C&Cs to upload the harvested data.

Once I have more details, I will most definitely add them to the alert. Thanks for your patience!
I understand, we don't want say out loud that URL of [some bank] has possible chance of being infected than others. Will looking at certificate issued by Symantec, Comodo etc of bank URL will help us know if the site is trustworthy or not?
 
  • Like
Reactions: Svoll and DardiM

Andra Zaharia

From Heimdal
Thread author
Verified
Jun 29, 2015
104
I understand, we don't want say out loud that URL of [some bank] has possible chance of being infected than others. Will looking at certificate issued by Symantec, Comodo etc of bank URL will help us know if the site is trustworthy or not?

Checking the certificate is a great way of knowing if it's safe.

I also recommend using dedicated browsers for online transactions to really minimize the risk. A good example is Bitdefender's SafePay. Other alternatives are listed here: 8 best secure browsers 2016: Private browsing guide

Multi-layered protection is key to protecting against almost any threat. A few key layers include: AV + VPN + password manager + browser security + DNS security. Of course, there are many more, but these are right at the core.

What would you add?
 
  • Like
Reactions: Svoll and DardiM

Vasudev

Level 33
Verified
Nov 8, 2014
2,247
Checking the certificate is a great way of knowing if it's safe.

I also recommend using dedicated browsers for online transactions to really minimize the risk. A good example is Bitdefender's SafePay. Other alternatives are listed here: 8 best secure browsers 2016: Private browsing guide

Multi-layered protection is key to protecting against almost any threat. A few key layers include: AV + VPN + password manager + browser security + DNS security. Of course, there are many more, but these are right at the core.

What would you add?
I'm little relieved after hearing that. BTW, I use Xubuntu for web browsing than windows.
 

Svoll

Level 13
Verified
Top Poster
Well-known
Nov 17, 2016
627

eXDj

Level 12
Verified
Aug 2, 2015
588
Checking the certificate is a great way of knowing if it's safe.

I also recommend using dedicated browsers for online transactions to really minimize the risk. A good example is Bitdefender's SafePay. Other alternatives are listed here: 8 best secure browsers 2016: Private browsing guide

Multi-layered protection is key to protecting against almost any threat. A few key layers include: AV + VPN + password manager + browser security + DNS security. Of course, there are many more, but these are right at the core.

What would you add?
And use Heimdal,no?
 
  • Like
Reactions: DardiM

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top