Sicurezza informatica Arriva Zeus con polymorphic encryption, gli antivirus non lo trovano più

Metatarso

Forumer storico
Fui facile profeta quando dicevo che la guerra per la sicurezza internet sta cambiando, siamo nell'imminenza di un salto di qualità di vari ordini di grandezza.
Ad es. questa: la prossima release di Zeus sarà automodificante, praticamente gli antivirus non lo trovano più. :titanic:


Trojan armed with hardware-based anti-piracy control
Zeus borrows page from Microsoft
Posted in Security, 12th March 2010 20:27 GMT

The latest version of the Zeus do-it-yourself crimeware kit goes to great lengths to thwart would-be pirates by introducing a hardware-based product activation scheme similar to what's found in Microsoft Windows.

The newest version with bare-bones capabilities starts at $4,000 and additional features can fetch as much as $10,000. The new feature is designed to prevent what Microsoft refers to as "casual copying" by ensuring that only one computer can run a licensed version of the program. After it is installed, users must obtain a key that's good for just that one machine.

"This is the first time we have seen this level of control for malware," according to an analysis of the latest Zeus version published this week by SecureWorks.

The hardware-based licensing system isn't the only page Zeus creators have borrowed from Microsoft. They've also pushed out multiple flavors of the package that vary in price depending on the capabilities it offers. Just as Windows users can choose between the lower-priced Windows 7 Starter or the more costly Windows 7 Business, bot masters have multiple options for Zeus.

For a mere $500 more, users can get a Zeus module that will allow them to received pilfered data in real time using the Jabber instant messaging client. A module that grabs data out of fields typed into Firefox fetches an extra $2,000, and a virtual network computing module that allows users to establish a fully functioning connection to an infected computer costs $10,000.

The VNC functionality fetches such a high price because it allows criminals to bypass some of the most advanced security measures, such a smartcards and other pieces of hardware that are used to authenticate high-value victims to a bank or other financial institution.

The latest version of Zeus is 1.3.3.7, SecureWorks researcher Kevin Stevens told El Reg. But the authors are already busy working on version 1.4, which is being beta tested. It offers polymorphic encryption that allows the trojan to re-encrypt itself each time it infects a victim, giving each one a unique digital fingerprint. As a result, anti-virus programs, which already struggle mightily to recognize Zeus infections, have an even harder time detecting the menace. ®

Trojan armed with hardware-based anti-piracy control ? The Register
 
con la nuova versione ne vedremo delle belle

in ogni caso già l'attuale versione dà del filo da torcere agli antivirus

Of Zeus-infected machines, about 31 per cent don't run AV at all and 14 percent run AV that's out of date. The remaining 55 per cent had AV programs that were up to date.
 
1268698557afraid.gif
1268698571afraid.gif
1268698600afraid.gif
:lol::lol:
 

Users who are viewing this thread

Back
Alto