OddJob Trojan hijacking banking sessions
By Tom Brewster,
A financial Trojan able to hijack online banking sessions has been spotted.
Trusteer named the new piece of malware OddJob, noting how it could keep banking sessions going even after customers believed they had logged off.
OddJob was used to log requests, grab full pages, terminate connections and inject data into web pages, with all activity relayed to a command and control server.
The malware was able to get hold of session ID tokens, which were used by banks to identify legitimate users, giving cyber criminals the cover they needed.
According to Trusteer, the most significant difference between OddJob and standard pieces of malicious software is that the former only requires the hacker to ride on an existing session, rather than logging into specific online banking computers.
The hackers, based in Eastern Europe, hit financial institutions in the US, Poland and Denmark.
However, the malware could easily be used to acquire funds from any country, explained Amit Klein, Trusteer's chief technology officer, who described OddJob as “fairly exceptional.”
“We definitely expect it to spread across Europe, into the UK etc,” he said.
Klein said the most impressive aspect of OddJob was its speed of evolution, telling IT PRO it will definitely improve as time goes on.
“The malware is still under development. [In the future] we don’t expect to see what we see right now,” Klein added.
OddJob has been seen spreading via drive-by downloads, where users head to a booby-trapped website and have malware installed on their systems without any knowledge of it.
Klein said Trusteer had been unable to report on OddJob until now due to ongoing investigations, although these have now come to a close.
The most well-known financial Trojan in the security industry is Zeus. Foreign Secretary William Hague recently admitted the UK Government had been targeted by the notorious malware.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Security Analysis & Insight
What is your password worth?
Would you be tempted to sell off company passwords for a fee? If not, seems like you're in the minority, acccording to research.
- Macs under attack?
- Intel: security inside
- Are you spending too much on IT security?
- Does the government want to snoop on your data?
- Eurocrats versus the cyber criminals
- The truth about spam
- Google and privacy: What’s the problem?
- Q&A: Symantec’s CISO on the source code hack
- RSA: Back from the breach?
Latest Security Reviews
Check Point 2210 Appliance review
Rating: ![]()
advertisement
Most popular
- UK regulator shuts down Angry Birds scam
- Apple iPad 3 vs iPad 2 head-to-head review
- IBM bans use of Siri on iPhones
- Chromebooks: What's gone wrong?
- HP plans massive job cuts
- EMC World 2012: Tucci declares Documentum is here to stay
- Dell EqualLogic PS6100XS review
- Macs and Android under malware threat
- RIM loses its head of sales
- Local fibre broadband needs common standards
Latest News Videos in Security
IT PRO Podcast: Are UK data protection laws flawed?
We bring in two experts to talk about the problems with UK data protection law and the way it is managed.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.






RE:
Despite the fact that Oddjob is not the same size as other Trojans such as SpyEye, its adaptive nature does raise a concern. Users need to remain aware of threats http://bit.ly/hqDLyY ensure that all patches are up to date, and be certain that they have signed out.
By MSC_247 on Friday Feb 25