<< Botnet Sending Fake UPS Invoices | Home | 08-08-08 Party on the 8s! All Night Party >>






July 24, 2008

New trojan guaranteed to evade detection?


Ars Technica is reporting that there is a new Trojan that's guaranteed to evade anti-viruses and filters.

The trojan is allegedly being sold for $1,300 online and supposedly carries a guarantee that it can evade detection by creating variants at a rate faster than the security companies can release definitions that can detect the malware.

Trojan horse
served by picapp.com
The new trojan itself is known as Limbo 2, and has been designed for both customization and variation. Prevx, the company that first detected it, reports that hackers are selling custom-designed variations of the Trojan to customers anxious to avoid detection. If a variant of Limbo 2 is detected, the Trojan can be shifted to a new, undetected approach. The payload itself remains unchanged throughout this process.

The actual infection at the heart of Limbo 2 is also a bit fancier than your average keylogger. Not only will it save and transmit any data you enter as part of a normal logon process, the Trojan will also display spoofed information boxes when users touch on a login page the Trojan finds interesting. The exact data Limbo 2 requests can vary, but includes credit card numbers, e-mail addresses, and additional login details. Any personal information found on the hard drive will also be packed up and shipped back to Botnet Central.

While the claims are out there, they're still plausible. It's hard to tell if they pulled it all off though and I have my doubts about it. Besides, is a guarantee from a malware author really worth anything?

[Malware bad guys tout new trojan guaranteed to evade filters]

Posted in Tech News by #!/usr/bin/geek at 2008-07-24 00:20 Eastern

Tags:


Comments
Post a comment

(Required)


(Valid Email Required)

Store my name and email in a cookie so I don't have to enter it again:


Comments are subject to the WyldRyde IRC Network Comment Policy

Links, URLs, and Web Addresses are prohibited!





Use of this form signifies your agreement to the WyldRyde IRC Network Comment Policy!


<< Botnet Sending Fake UPS Invoices | Home | 08-08-08 Party on the 8s! All Night Party >>