Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - It's all Geek to me.

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews




spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Macrium Reflect FREE Edition
3. Smart Defrag
4. Visual C++ Redistributable Runtimes AIO Repack
5. Visual C++ Runtime Installer (All-In-One)
6. McAfee Removal Tool (MCPR)
7. MusicBee
8. Rufus
9. K-Lite Mega Codec Pack
10. Sergei Strelec's WinPE
More >>

top reads

Star How to Disable 1-Click Ordering on Amazon (and Avoid Surprise Charges)

Star How to Fix Shallow Paint Layer Depth in Bambu Studio

Star Aviator Betting Game Secrets: Unlock 97% RTP & Triple Your Wins

Star Windows Recall: What It Is, Why Hackers Will Love It, and How to Stay Safe

Star Star Trek Fleet Command Promo Codes: Redeem Codes for Free Shards, Blueprints And Resources

Star How To Use VLC Media Player to Trim Video Clips

Star What Is the $WinREAgent Folder and Can I Delete It?

Star Swear Your Way to Better Search Results

Star How to Get a Dark Start Menu and Taskbar in Windows 10 & 11

Star Enable, Disable, Manage, Delete or Create a System Restore Point


MajorGeeks.Com » News » January 2013 » The Shylock banking trojan now travels by Skype

The Shylock banking trojan now travels by Skype


Contributed by: Email on 01/18/2013 03:56 PM [ comments Comments ]


The banking trojan Shylock has found itself a new distribution channel – Skype. The security firm CSIS recently discovered a Shylock module called "msg.gsm" trying to use the VoIP software to infect other computers. If successful, the malware then sets up a typical backdoor. The module tries to send Shylock as a file, bypassing warnings from the Skype software by confirming them itself and cleaning any generated messages from the Skype history.

Once the trojan has been transferred it connects to a command and control server which can ask it to install a VNC server allowing remote control of the computer, get cookies, inject HTTP code into web sites being browsed, spread Shylock over removable drives, or upload files to a server.

The epicenter of infections is, according to CSIS, the UK. The operators are preferring to focus on just a few countries rather than handling widespread random infections in many countries. The use of chat-based transmission, be it Skype or MSN Messenger or Yahoo, tends to increase that focus as people stay connected with friends who are usually within their own region.

Using VirusTotal, the system which runs code past a range of anti-virus software, the Skype module was not detected by any of the 46 different scanning engines on Thursday morning. At the time of writing, the most recent VirusTotal test shows 15 of the engines now detecting it. CSIS calls Shylock one of the most advanced online banking trojans and one that is being continually updated with new features. They also note that Microsoft announcing that it is migrating Messenger users to Skype and the emergence of a Skype-enabled Shylock "does not seem completely coincidental".






« Florida Friday: Mugshot: Reckless driver jumps from 7 Mile Bridge in Florida · The Shylock banking trojan now travels by Skype · Silent installs of add-ons still possible in Firefox »




Comments
comments powered by Disqus

MajorGeeks.Com » News » January 2013 » The Shylock banking trojan now travels by Skype

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition