All the latest UK technology news, reviews and analysis

Researchers dissect Tatanga malware

by Shaun Nichols

08 Mar 2011

Be the first to comment

  • Tweet this

Security researchers are beginning to analyse a banking Trojan that made headlines last week.

Known as 'Tatanga', the malware uses key-logging and remote control tools to harvest user log-in credentials.

Two researchers with security firm Trend Micro have been able to infiltrate one of the malware network's command-and-control servers.

Senior threat researchers David Sancho and Kevin Stevens said in a recent report that the malware appears to target banking sites, but also contains other potentially dangerous components.

The researchers noted that the Tatanga malware could also be used by its controllers to collect detailed information on infected machines, and force infected systems to take part in a distributed denial-of-service attack.

The primary function of the malware, however, is banking attacks. The Trend researchers said that, in addition to attempting to pull account data from browser transmissions, the malware attempts to record and upload video of password entry to thwart possible security protections.

Funds from the compromised accounts are automatically sent to accounts controlled by 'money mules' who can presumably then launder the stolen cash.

Researchers explained that the server controlling the malware has been operational since July 2010, indicating that the infection may have been operating undiscovered for some time.

Of particular interest to the researchers was the extremely detailed information the infection collects on users.

"The server keeps track of each client's version and build number, operating system and something called 'malware count', which is presumably the amount of other malware installed," the researchers wrote.

"We don't know who might be detecting them, so it is a puzzling statistic."

 

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

31%

1%

11%

57%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Web Development Manager / Team Leader / PHP / MySQL

Development Manager / PHP Developer / MySQL / LAMP...

Process Expert for Information/Content Management

Process Expert for Information/Content Management...

SSIS Developer / Implementation Specialist

SQL Server / SSIS / ETL / T-SQL Data Migration A...

Linux Systems Administrator / Network Systems Admin

Linux Systems Administrator / Linux CentOS / Network...

To send to more than one email address, simply separate each address with a comma.