A type of data-stealing malware called Vawtrak is spreading in countries around the world, controlling thousands of computers while silently draining the bank accounts of its victims.
Analysis of the malware by James Wyke, Senior Threat Researcher with SophosLabs UK, indicates that the people behind Vawtrak are targeting banks and other companies in a very methodical way in a number of countries, including some that aren’t commonly targeted by banking malware.
In his fascinating new research paper on the subject, Vawtrak – International Crimeware-as-a-Service, James enlightens us about the mechanics of this cybercriminal enterprise, and the steps taken by this crafty and deceptive malware as it steals account details and transaction tokens directly from victims when they visit the websites of their financial institutions.
Vawtrak has followed the success of previous financial bot malware like Zeus and Gameover to become one of the most popular crime kits around. Vawtrak’s owners are operating a highly successful business, running specific campaigns and adding new targets as demand requires.
Vawtrak was the second most popular malware distributed by web-based exploit kits (i.e., by malicious drive-by downloads) during September to November 2014, according to SophosLabs telemetry. It represented 11% of all malware SophosLabs saw distributed in this way during that time period.
Beyond its technical breakdown of the malware’s functions, James’s research paper is a must-read for anyone who wants to understand how modern financial cybercrime works and how it has become such a big threat. Download the full report here: Vawtrak – International Crimeware-as-a-Service.
Protection against Vawtrak
Vawtrak is an example of how dangerous malware can get around banks’ security by preying on unprotected users. Be cautious when banking online and make sure your computer and applications are patched with the latest security updates. In addition, endpoint protection software (antivirus) is a must.
It also spreads through spam messages that are designed to trick people into downloading malicious attachments, so never open an attachment you aren’t expecting.
Whenever possible, ask financial institutions to provide two-factor authentication. And be alert for suspicious behaviors, like being asked for information that you don’t normally have to provide when initiating an online transaction.
Sophos customers are protected against Vawtrak by our endpoint, server and network protection products.
About SophosLabs
SophosLabs is the global network of threat centers staffed by Sophos researchers and analysts. Keep up to date with our latest industry-leading research, technical papers, and security advice at Naked Security and the Sophos Blog.
Sign up for our newsletter by filling in your email address at the top right of the blog’s webpage. Follow us on your favorite social media networks, chat with us in our forums, download our informative podcasts, or sign up for our RSS feeds.
ste williams – Information-stealing ‘Vawtrak’ malware evolves, becomes more evasive
[…] as we described in detail in our recent technical paper, is a dangerous banking Trojan that is actively being updated and improved on a regular […]
Information-stealing ‘Vawtrak’ malware evolves, becomes more evasive | taurseti
[…] as we described in detail in our recent technical paper, is a dangerous banking Trojan that is actively being updated and improved on a regular […]
Crimeware-as-a-Service offers custom targeting | Templar Shield
[…] But Sophos was able to find out quite a bit about how the Vawtrak platform works and what it is being used for, information which was released last week in a research paper. […]
Crimeware-as-a-Service offers custom targeting | Protect Your PC | Tips, Advice, and support. Protect Your PC | Tips, Advice, and support.
[…] But Sophos was able to find out quite a bit about how the Vawtrak platform works and what it is being used for, information which was released last week in a research paper. […]
Publications, études, rapports 2015 S01 | La Mare du Gof
[…] victims. (…).» Date du 18/12, mais étais passé à côté la semaine dernière. Source : blogs.sophos.com/2014/12/18/sophoslabs-research-spotlights-rising-threat-of-vawtrak-financial-malwar… Billets en relation : 29/09/2014. Organised crime groups exploiting hidden internet in online […]
"Obamacare" phishing email leads to banking malware?
[…] is a notorious family of malware that we covered in some detail late last […]
ste williams – "Obamacare" phishing email leads to banking malware
[…] is a notorious family of malware that we covered in some detail late last […]
Why security is failing #1: Incomplete protection | Sophos Blog
[…] that have been affected recently by Cryptowall and other ransomware, banking Trojans like Vawtrak, and targeted […]
Net Universe ǀ Connecting Solutions – Why security is failing #1: Incomplete protection
[…] that have been affected recently by Cryptowall and other ransomware, banking Trojans like Vawtrak, and targeted […]
Internet Crime Fighters Organization Vawtrak malware - Internet Crime Fighters Organization
[…] as we described in detail in our recent technical paper, is a dangerous banking Trojan that is actively being updated and improved on a regular […]