Advertisement
Promo

Security threats Toolkit

Trojan logs e-banking habits

Dan Ilet ZDNet.co.uk

Published: 11 Nov 2004 14:45 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security experts say they have discovered a Trojan horse that records e-banking user details and Web surfing habits.

Antivirus company Sophos is warning that the Banker-AJ Trojan is targeting online customers of banks such as Abbey, Barclays, Egg, HSBC, Lloyds TSB, Nationwide and NatWest.

The company said that once installed, the Trojan waits for users to visit their online banking Web sites, captures passwords and takes screenshots of the session. The information is then relayed to the hackers behind the ploy, who use the data to steal money.

"It's the next generation of phishing attacks," said Graham Cluley, senior technology consultant for Sophos. "These rely on people going to real legitimate sites. Once the Trojan determines that you've gone there, it starts taking keystroke logs and snaps shots of machines and sends it back to hackers."

But Barclays Bank said it had seen the technique before. A spokeswoman for the company said: "This type of Trojan is something [we] have been aware of for some time. We are working with industry to identify the next steps to help combat fraud and are interested in educating customers."

Sophos also said it had seen a similar Trojan (Tofger) a few months ago, but the technique had mainly been used in Brazil.

"We did see another one a few months ago," added Cluley. "Some of the Brazilian ones just wait for the user to look at a Web site with the word 'bank' in, but this one specifically targets many well known UK banks, and that makes it notable."

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
98 out of 185 people found this useful



Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

3 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters