
Incapsula Protection
Printer Backdoor
Hardware malware
Nuclear Plant hacked
Java zero-day exploit
RedHack hacker
1ffb
Sign up for Updates
Shylock malware : Undetectable virus stealing bank account information
on
Shylock, a financial malware platform discovered by Trusteer in 2011, is a non-Zeus-based information-stealing trojan that improved methodology for injecting code into additional browser processes to take control of a computer, and an improved evasion technique to prevent malware scanners from detecting its presence.
Why this Name ? Shylock named after the ruthless money lender in Shakespeare’s The Merchant of Venice, also deletes its installation files, runs solely in memory, and begins the process again once the infected machine reboots.
Shylock has gained a new trick: The ability to detect whether it’s running in a virtual machine (VM) that is being analyzed by malware researchers.
What New ? Latest Shylock dropper detects a remote desktop environment by feeding invalid data into a certain routine and then observing the error code returned. It uses this return code to differentiate between normal desktops and other “lab” environments. In particular, when executed from a remote desktop session the return code will be different and Shylock won’t install. It is possible to use this method to identify other known or proprietary virtual/sandbox environments as well.
However, it is unclear how long such a trick will help it evade detection, because evasion tactics aren’t actually that effective. In February researchers found that none of the world’s top 20 malware families except for Conficker try to detect virtual machines.
About Author:
Mohit Kumar aka ‘Unix Root’ is Founder and Editor-in-chief of ‘The Hacker News’. He is a Security Researcher and Analyst, with experience in various aspects of Information Security. His editorials always get people thinking and participating in the new and exciting world of cyber security. Other than this : He is an Internet Activist, Strong supporter of Anonymous & Wikileaks. His all efforts are to make internet more Secure. Follow him @ Twitter | LinkedIn | Google | Email
Tags:
Antivirus product
,
bank hacked
,
hacking news
,
Malware
,
Password hack
,
Security News
,
Shylock
,
stealing bank account
,
Undetectable malware
The content of – Shylock malware : Undetectable virus stealing bank account information and other Information in this article is only for Educational Purpose, provided by various legit sources and deep analysis of our Security Research Team. Please feel free to Contact us. Thank You !
Older Post
‘; var pageArea = document.getElementsByName(“pageArea”);
var blogPager = document.getElementById(“blog-pager”); if(postNum 0)
html =”;
if(blogPager)
blogPager.innerHTML = html;
} function showpageCount2(json) var thisUrl = home_page_url;
var htmlMap = new Array();
var isLablePage = thisUrl.indexOf(“/search/label/”)!=-1;
var thisLable = isLablePage ? thisUrl.substr(thisUrl.indexOf(“/search/label/”)+14,thisUrl.length) : “”;
thisLable = thisLable.indexOf(“?”)!=-1 ? thisLable.substr(0,thisLable.indexOf(“?”)) : thisLable;
var thisNum = 1;
var postNum=1;
var itemCount = 0;
var fFlag = 0;
var eFlag = 0;
var html= ”;
var upPageHtml =”;
var downPageHtml =”; var labelHtml = ‘
‘;
}else
upPageHtml = ‘
‘;
fFlag++;
} if(p==(thisNum-1))
html += ‘
‘+thisNum+’
‘;
else
if(p==0)
html = labelHtml+’1′;
else
html += ‘
‘;
} if(eFlag ==0 && p == thisNum)
downPageHtml = ‘
‘;
eFlag++;
}
} if(thisNum>1)
if(!isLablePage)
html = ”+upPageHtml+’ ‘+html +’ ‘;
else
html = ”+upPageHtml+’ ‘+html +’ ‘;
} html = ‘
Pages (‘+(postNum-1)+’)'+html; if(thisNum’; var pageArea = document.getElementsByName(“pageArea”);
var blogPager = document.getElementById(“blog-pager”); if(postNum 0)
html =”;
if(blogPager)
blogPager.innerHTML = html;
}
Loading
;
More:
Shylock malware : Undetectable virus stealing bank account information

