Reply to topic  [ 5 posts ] 
Linux Trojan 
Author Message
What's a life?
User avatar

Joined: Thu Apr 23, 2009 8:25 pm
Posts: 10691
Location: Bramsche
Reply with quote
There is a new Linux trojan designed to steal banking and credit card information.

http://www.zdnet.com/linux-desktop-troj ... 000019175/

Quote:
Here the name of the game is to grab your personal login and password data with a "Form grabber" as you enter it into your bank or other online system. This information consists of your stolen credentials, the timestamp of when you visited a site, which Web sites you visited, and possibly your Web browser's cookies. Finally, all this is then passed on over the Internet to a command-and control server. From there the crooks can get to work selling your information to people who will start running up your credit-card bills.


Quote:
At this point, some Linux users may start pooh-poohing this as yet another case of virus FUD. It's not. Hand of Thief really is out there. I should know. Someone tried to give a case of it to me earlier today.


Quote:
By the way, that wasn't a mistake when I said "sales agent." Like a lot of modern malware, Hand of Thief is designed by criminals for criminals. As Kessem wrote, "This malware is currently offered for sale in closed cybercrime communities for $2,000 USD (€1,500 EUR) with free updates." When it goes "commercial," its "price is expected to rise to $3,000 USD (€2,250 EUR), plus a hefty $550 per major version release. "

_________________
"Do you know what this is? Hmm? No, I can see you do not. You have that vacant look in your eyes, which says hold my head to your ear, you will hear the sea!" - Londo Molari

Executive Producer No Agenda Show 246


Fri Aug 09, 2013 6:35 am
Profile ICQ
Legend
User avatar

Joined: Fri Apr 24, 2009 2:02 am
Posts: 29240
Location: Guantanamo Bay (thanks bobbdobbs)
Reply with quote
While it might be a threat to Linux users wouldn't the numbers of linux users be relatively low? I thought that most Linux machines are servers.

_________________
Do concentrate, 007...

"You are gifted. Mine is bordering on seven seconds."

https://www.dropbox.com/referrals/NTg5MzczNTk

http://astore.amazon.co.uk/wwwx404couk-21


Fri Aug 09, 2013 7:06 am
Profile
Site Admin
User avatar

Joined: Thu Apr 23, 2009 5:53 pm
Posts: 8603
Location: location, location
Reply with quote
Amnesia10 wrote:
While it might be a threat to Linux users wouldn't the numbers of linux users be relatively low? I thought that most Linux machines are servers.


A lot of government machines in other countries & defence personnel machines are Linux (so they're not reliant on a single vendor).
Developing countries also can be heavily reliant on Linux due OEM MS costs.

_________________
Support X404, use our Amazon link
Get your X404 tat here
jonlumb wrote:
I've only ever done it with a chicken so far, but if required I wouldn't have any problems doing it with other animals at all.


Fri Aug 09, 2013 7:39 am
Profile WWW
What's a life?
User avatar

Joined: Thu Apr 23, 2009 8:25 pm
Posts: 10691
Location: Bramsche
Reply with quote
A lot of people also use Linux, either in a separate partition/virtual machine or a Live CD specifically for things like Banking, because until now it has been secure against such attacks.

A Live CD would still probably be relatively secure, because you would need to have email or a social network running (either in web browser or dedicated application) in order to receive the trojan. When the machine is shut down, the trojan would be removed from memory and when the system is restarted, the trojan would not be around, so the user would need to infect themselves again.

With a secondary partition/virtual machine, if the user falls for it once, it will be there for every future session until manually removed.

That said, if they are using the VM specifically for financial transactions, then they shouldn't be browsing emails or reading social networks on their "secure" platform.

_________________
"Do you know what this is? Hmm? No, I can see you do not. You have that vacant look in your eyes, which says hold my head to your ear, you will hear the sea!" - Londo Molari

Executive Producer No Agenda Show 246


Fri Aug 09, 2013 7:45 am
Profile ICQ
Legend
User avatar

Joined: Fri Apr 24, 2009 2:02 am
Posts: 29240
Location: Guantanamo Bay (thanks bobbdobbs)
Reply with quote
saspro wrote:
Amnesia10 wrote:
While it might be a threat to Linux users wouldn't the numbers of linux users be relatively low? I thought that most Linux machines are servers.


A lot of government machines in other countries & defence personnel machines are Linux (so they're not reliant on a single vendor).
Developing countries also can be heavily reliant on Linux due OEM MS costs.

I doubt that these people will have a significant online banking presence. This is more targeted at Linux users in the West. I fully appreciate the benefits of linux especially for governments and companies, as you mentioned the OS licenses can be horrendous.

_________________
Do concentrate, 007...

"You are gifted. Mine is bordering on seven seconds."

https://www.dropbox.com/referrals/NTg5MzczNTk

http://astore.amazon.co.uk/wwwx404couk-21


Fri Aug 09, 2013 8:57 am
Profile
Display posts from previous:  Sort by  
Reply to topic   [ 5 posts ] 

Who is online

Users browsing this forum: No registered users and 8 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
cron
Powered by phpBB® Forum Software © phpBB Group
Designed by ST Software.