Retefe Revisited: Banking trojan reemerges, adopts new set of tools
#1
Quote:Researchers have noticed a recent upswing in attacks against banks featuring the Retefe banking trojan, following what was apparently a fairly quiet 2018 for the malware.
 
The trojan is historically known for targeting the banking industry in countries like Austria, Sweden, Switzerland and the UK. Rather than using malicious web injects to execute man-in-the-browser attacks — like many banking trojans do — it victimizes users by using a proxy to route online traffic intended for legitimate banking websites to malicious sites instead.

In April 2019, the malware began focusing its efforts on Swiss and German online banking customers using either Windows- or macOS-based machines, according to a blog post published today by the Proofpoint Threat Insight Team and company researcher Bryan Campbell.
 
This latest campaign changes some of the malware’s functionality as well. For instance, instead of using TOR for its proxy redirection and command-and-control set-up, Retefe uses Stunnel, an open-source application that acts as a proxy and universal TLS/SSL tunneling service.

“It is not clear why Retefe’s authors have now deprecated Tor in favor of stunnel. However, we suspect that the use of a dedicated tunnel rather than Tor makes for a more secure connection because it eliminates the possibility of snooping on the hops between Tor nodes,” Proofpoint surmises in the blog post. “Tor is also a ‘noisier’ protocol and thus would be easier to detect in an enterprise environment than Stunnel, which would appear as any other outbound SSL connection.”

SOURCE: https://www.scmagazine.com/home/security...__trashed/
[-] The following 2 users say Thank You to silversurfer for this post:
  • harlan4096, ismail
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Hasleo software (formerly called EasyUE...
Hasleo WinToUSB V10....jasonX — 16:10
AxCrypt 3.0.0.94
AxCrypt 3.0.0.94: ...harlan4096 — 11:41
NVIDIA GeForce Game Ready 596.49 driver
Highlights  Gam...harlan4096 — 11:40
AMD launches six new Ryzen PRO 9000 CPUs...
AMD Ryzen PRO 9000...harlan4096 — 11:39
AMD HDMI 2.1 DSC patches could bring 4K ...
AMDGPU HDMI 2.1 pa...harlan4096 — 11:37

[-]
Birthdays
Today's Birthdays
avatar (38)owysykan
avatar (49)beautgok
Upcoming Birthdays
avatar (28)akiratoriyama
avatar (48)Jerrycix
avatar (40)awedoli
avatar (82)WinRARHowTo
avatar (39)axuben
avatar (40)ihijudu
avatar (45)tiojusop
avatar (42)Damiennug
avatar (40)acoraxe
avatar (49)contjrat
avatar (44)knigiJow
avatar (46)1stOnecal
avatar (50)Mirzojap
avatar (36)idilysaju
avatar (40)GregoryRog
avatar (45)mediumog
avatar (40)odukoromu
avatar (46)Joanna4589

[-]
Online Staff
There are no staff members currently online.

>