Menu
New powerful banking malware called Dyreza emerges

New powerful banking malware called Dyreza emerges

The malware uses browser hooking to conduct a man-in-the-middle attack, security companies say

A powerful new type of banking malware called Dyre or Dyreza is being distributed through spam messages containing malicious links to a supposed invoice.

A powerful new type of banking malware called Dyre or Dyreza is being distributed through spam messages containing malicious links to a supposed invoice.

Security researchers said they've spotted a new type of banking malware that rivals the capabilities of the infamous Zeus malware.

The malware, which is being called "Dyreza" or "Dyre," uses a man-in-the-middle attack that lets the hackers intercept unencrypted web traffic while users mistakenly think they have a secure connection with their online banking site.

Although Dyreza has similarities with Zeus, "we believe this is a new banker trojan family and not yet another offspring from the Zeus source code," according to a writeup by CSIS, a Danish security company.

Dyreza uses a technique called "browser hooking" to view unencrypted web traffic, which involves compromising a computer, capturing unencrypted traffic and then stepping in when a user tries to make a secure SSL (Secure Sockets Layer) connection with a website.

During an attack by Dyreza, a user thinks their authentication credentials are going to a legitimate bank, but the malware actually redirects the traffic to their own servers, wrote Ronnie Tokazowski, a senior researcher at PhishMe, another security company that has studied the attack. Users mistakenly think they have connected over SSL to their bank's server.

Dyreza is programmed to intercept credentials when a person navigates to the websites of Bank of America, NatWest, Citibank, RBS and Ulsterbank, wrote Peter Kruse, who is head of CSIS's eCrime Unit and CTO for CSIS's Security Group.

The malware is being distributed through spam messages, some of which supposedly contain an invoice as a ".zip" file. To help evade URL scanners that might block messages with known suspicious domains, the attackers have been hosting the malware on legitimate domains.

One of the services that has been abused is LogMeIn's "cubby.com," which is a file storage service, Tokazowski wrote. Dropbox had been used in the past, but Tokazowski wrote that the service moves quickly to block phishing links. Using trusted domains from legitimate services can help extend the life of a malicious link.

It appears the attackers have also set up other infrastructure to facilitate the transfer of money from victims' accounts. Kruse wrote that CSIS managed to locate some of the command-and-control servers for Dyreza, uncovering a customized money mule panel with accounts in Riga, Latvia. Money mules are people who agree to briefly hold stolen funds in their own accounts before forwarding the funds elsewhere.

Kruse wrote it was unclear if the people who wrote Dyreza are holding it close and using it for themselves or are renting it out to other criminal outfits, as was done with Zeus.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags fraudmalwarephishmeCSIS

Events

Featured

Slideshows

Meet the Reseller News 30 Under 30 Tech Awards 2020 winners

Meet the Reseller News 30 Under 30 Tech Awards 2020 winners

This year’s Reseller News 30 Under 30 Tech Awards were held as an integral part of the first entirely virtual Emerging Leaders​ forum, an annual event dedicated to identifying, educating and showcasing the New Zealand technology market’s rising stars. The 30 Under 30 Tech Awards 2020 recognised the outstanding achievements and business excellence of 30 talented individuals​, across both young leaders and those just starting out. In this slideshow, Reseller News honours this year's winners and captures their thoughts about how their ideas of leadership have changed over time.​

Meet the Reseller News 30 Under 30 Tech Awards 2020 winners
Reseller News Exchange Auckland: Beyond the myths — how partners can master cloud security

Reseller News Exchange Auckland: Beyond the myths — how partners can master cloud security

This exclusive Reseller News Exchange event in Auckland explored the challenges facing the partner community on the cloud security frontier, as well as market trends, customer priorities and how the channel can capitalise on the opportunities available. In association with Arrow, Bitdefender, Exclusive Networks, Fortinet and Palo Alto Networks. Photos by Gino Demeer.

Reseller News Exchange Auckland: Beyond the myths — how partners can master cloud security
Reseller News welcomes industry figures at 2020 Hall of Fame lunch

Reseller News welcomes industry figures at 2020 Hall of Fame lunch

Reseller News welcomed 2019 inductees - Leanne Buer, Ross Jenkins and Terry Dunn - to the fourth running of the Reseller News Hall of Fame lunch, held at the French Cafe in Auckland. The inductees discussed the changing face of the IT channel ecosystem in New Zealand and what it means to be a Reseller News Hall of Fame inductee. Photos by Gino Demeer.

Reseller News welcomes industry figures at 2020 Hall of Fame lunch
Show Comments