Osiris Banking Trojan Displays Modern Malware Innovation
#1
Quote:Osiris’ fundamental makeup positions it in the fore of malware trends, despite being based on old source code that’s been knocking around for years.

After staying dormant for few years, the Kronos banking trojan resurfaced in July in a form dubbed Osiris. A wider analysis of how the banking trojan is evolving shows innovative development on the part of its authors, with an eye to broader malware trends.

Osiris first appeared in July in three distinct campaigns targeting Germany, Japan and Poland over the summer. It was clear that it’s based off of the Kronos malware which led the financial crime pack for many quarters after it surfaced in 2014 (it is itself a descendant of the infamous Zeus banking code).

While the behaviors exhibited by the newly spawned banking trojan are similar to many other prevalent banking malware (for instance, it implements Zeus-style G/P/L web-injects, a keylogger and a VNC server, according to Securonix researcher Oleg Kolesnikov), there are also significant differences.

For one, it uses encrypted Tor traffic for command-and-control (C2). “The malicious payload spawns multiple processes named ‘tor.exe’ and connects to multiple distinct host (Tor nodes) located in different countries,” Kolesnikov said in a post Tuesday on Osiris.

Source: https://threatpost.com/osiris-banking-tr...on/137393/
[-] The following 2 users say Thank You to silversurfer for this post:
  • Dino101, harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
LibreOffice 26.2.4
Berlin, 5 June 202...harlan4096 — 12:17
Surfshark VPN : Award-winning VPN servi...
Surfshark Apps Ver...jasonX — 11:34
K-Lite Codec Pack 19.7.5 / 19.7.5 Update
Changes in 19.7.5 ...harlan4096 — 10:19
Brave v1.91.168 (Chromium 149.0.7827.54)
Release v1.91.168 ...harlan4096 — 10:17
Vivaldi 8.0 Build 4033.44
Vivaldi 8.0 Build ...harlan4096 — 10:16

[-]
Birthdays
Today's Birthdays
avatar (42)tapedDow
Upcoming Birthdays
avatar (48)BrantgoG
avatar (49)rapedDow
avatar (44)Johnsonsyday
avatar (49)Groktus
avatar (41)efodo
avatar (39)Tedscolo
avatar (46)brakasig
avatar (51)smudloquask
avatar (46)benchJem
avatar (45)JamesReshy
avatar (47)Francisemefe
avatar (40)leoniDup
avatar (39)Patrizaancem
avatar (39)biobdam
avatar (42)zacforat
avatar (47)NemrokReks
avatar (38)Barrackleve
avatar (40)Julioagopy
avatar (50)aolaupitt2558
avatar (48)vadimTob
avatar (38)leannauu4
avatar (40)storoBox
avatar (48)kinotHeemn
avatar (39)Ceballos1976
avatar (40)efynu
avatar (32)horancos

[-]
Online Staff
There are no staff members currently online.

>