Username: Save?
Password:
Home Forum Links Search Login Register*
    News: Keep The TechnoWorldInc.com Community Clean: Read Guidelines Here.
Recent Updates
[April 12, 2025, 01:54:20 PM]

[April 12, 2025, 01:54:20 PM]

[April 12, 2025, 01:54:20 PM]

[April 12, 2025, 01:54:20 PM]

[March 12, 2025, 03:05:30 PM]

[March 12, 2025, 03:05:30 PM]

[March 12, 2025, 03:05:30 PM]

[March 12, 2025, 03:05:30 PM]

[January 03, 2025, 03:29:12 PM]

[January 03, 2025, 03:29:12 PM]

[January 03, 2025, 03:29:12 PM]

[January 03, 2025, 03:29:12 PM]

[November 08, 2024, 04:31:03 PM]
Subscriptions
Get Latest Tech Updates For Free!
Resources
   Travelikers
   Funistan
   PrettyGalz
   Techlap
   FreeThemes
   Videsta
   Glamistan
   BachatMela
   GlamGalz
   Techzug
   Vidsage
   Funzug
   WorldHostInc
   Funfani
   FilmyMama
   Uploaded.Tech
   Netens
   Funotic
   FreeJobsInc
   FilesPark
Participate in the fastest growing Technical Encyclopedia! This website is 100% Free. Please register or login using the login box above if you have already registered. You will need to be logged in to reply, make new topics and to access all the areas. Registration is free! Click Here To Register.
+ Techno World Inc - The Best Technical Encyclopedia Online! » Forum » THE TECHNO CLUB [ TECHNOWORLDINC.COM ] » Techno News
 A good Carberp is hard to find - Context Information Security lead reseach into
Pages: [1]   Go Down
  Print  
Author Topic: A good Carberp is hard to find - Context Information Security lead reseach into  (Read 498 times)
NeonDrum
Super Elite Member
******


Karma: 0
Offline Offline

Posts: 1403


View Profile WWW Email


January 17th 2012 - Increasingly sophisticated financial malware such as the Carberp Trojan is becoming more and more difficult to detect and eliminate, warns researchers at Context Information Security. Designed to steal log-in and account information and harvest credentials for email and social-networking sites, Carberp, like its more well know predecessors Zeus and Spyeye, infects machines through malicious files such as PDFs and Excel documents or drive-by downloads.

In most cases Carberp will persist undetected by antivirus software on the infected machine using advanced stealth, anti-debugging and rootkit techniques and is controlled from a central administrator control panel that allows the attacker to mine the stolen data. Carberp is also part of a botnet that can take full control over infected hosts, while its complicated infection mechanisms and extensive functionality make it a prime candidate for more targeted attacks.

The malware uses multiple layers of obfuscation and encryption to remain hidden and prevent analysis. Once embedded and decrypted, the real infection begins with malicious file dropping and process injection steps that provide a backdoor to the host under attack.

“The advanced infection capabilities of Trojans such as Carberp require detailed knowledge of how they operate to detect and analysis attacks,” says Michael Jordon, research and development manager at Context. “While many banks are now using tools such as Rapport from Trusteer to mitigate the risk of financial malware by protecting web communication with customers and preventing the stealing of account credentials, we need to stay one step ahead or at least keep pace with the malware developers to reduce their impact.”

While there is a large body of knowledge around Zeus and Spyeye, the information security industry is still building up detailed picture of newer Trojans such as Carberp. Context researchers are at forefront of this work and have published a series of blogs to detail the workings of new generation financial malware and provide advice how it is possible to detect infection and mitigate the threats.

The latest blog focused on, ‘From Infection to Persistence’ can be seen at: http://www.contextis.com/research/blog/malware2/

About Context
Context Information Security is an independent security consultancy specialising in both technical security and information assurance services. Founded in 1998, the company’s client base has grown steadily based on the value of its product-agnostic, holistic approach and tailored services combined with the independence, integrity and technical skills of its consultants. The company’s client base now includes some of the most prestigious blue chip companies in the world, as well as government organisations. As best security experts need to bring a broad portfolio of skills to the job, Context staff offer extensive business experience as well as technical expertise to deliver effective and practical solutions, advice and support. Context reports always communicate findings and recommendations in plain terms at a business level as well as in the form of an in-depth technical report.
www.contextis.com

Issued by:
Context Information Security,
Tel: + 44 (0)20 7537 7515,
email: blogs[at]contextis[dot]com
www.contextis.com

For more information for editors, please contact:
Peter Rennison / Allie Andrews
PRPR, Tel + 44 (0)1442 245030 / 07831 208109
pr[at]prpr[dot]co.uk / allie[at]prpr[dot]co.uk

Distributed on behalf of PRPR by NeonDrum news distribution service (http://www.neondrum.com)

Logged

Pages: [1]   Go Up
  Print  
 
Jump to:  

Copyright © 2006-2023 TechnoWorldInc.com. All Rights Reserved. Privacy Policy | Disclaimer
Page created in 0.08 seconds with 23 queries.