Firstpost
  • Home
  • Video Shows
    Vantage Firstpost America Firstpost Africa First Sports
  • World
    US News
  • Explainers
  • News
    India Opinion Cricket Tech Entertainment Sports Health Photostories
  • Asia Cup 2025
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
Trending:
  • Nepal protests
  • Nepal Protests Live
  • Vice-presidential elections
  • iPhone 17
  • IND vs PAK cricket
  • Israel-Hamas war
fp-logo
New 'Mousetrap Trojan' Steals Your Money By Chain Reaction
Whatsapp Facebook Twitter
Whatsapp Facebook Twitter
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
  • Home
  • Business
  • Biztech
  • New 'Mousetrap Trojan' Steals Your Money By Chain Reaction

New 'Mousetrap Trojan' Steals Your Money By Chain Reaction

FP Archives • February 2, 2017, 23:31:27 IST
Whatsapp Facebook Twitter

New script downloads an applet, that downloads a downloader Trojan, that downloads a banker Trojan, that downloads… pure malice.

Advertisement
Subscribe Join Us
Add as a preferred source on Google
Prefer
Firstpost
On
Google
New 'Mousetrap Trojan' Steals Your Money By Chain Reaction

Bitdefender, the provider of innovative antivirus solutions, alerts about the Mousetrap Trojan which steals one’s money by chain reactions.

A new bank-robber Trojan, like a Mafia boss who avoids the cops by ordering heists through an intricate chain of command, sets of a series of downloads and installations to rob your bank account while dodging antivirus software.

The new Mousetrap campaign starts as Java applets injected in popular websites infect visitors. The malicious applet, Trojan.Downloader.Java.OpenConnection. BA, disguised as Adobe Flash Player, pretends to be clean html files to ensure its execution along with the opening of the piggybacked html page. Once executed, the applet downloads and installs another malicious executable file on the machine of the website visitors.

STORY CONTINUES BELOW THIS AD

The attackers likely use 0-day vulnerabilities in blogging web applications or brute-force weak administrator passwords to add their code in the header file.

The downloaded file (Trojan.Generic.KD.218227), written in Visual Basic and packed with UPX, is saved in a writeable location on the user’s machine with the name temp_flash_file.phx. It downloads and installs a banker from a list (hardcoded in the downloader) of a dozen available links that lead to different banker Trojans.

More from Biztech
Future Group - Reliance Retail Deal approved by CCI Future Group - Reliance Retail Deal approved by CCI RBI ban on cryptocurrencies takes effect; prohibition could force investors to tap the black market RBI ban on cryptocurrencies takes effect; prohibition could force investors to tap the black market

To ensure automatic launch, the banker creates a shortcut to itself in “%Start Menu%ProgramsStartup” with an empty name with “.lnk” extension. Each time the system starts, all programs with shortcuts added in that folder are automatically initiated as well … including the banker.

Once on the system, the banker updates itself by downloading newer versions from a second list of links. The updates hide out in different locations so that if one is detected, the rest can still be accessed.

Of course, these locations can also be reached directly by the malware. But not accessing them directly makes it harder for AV vendors to trace the source of the malware.

For example, once anti-virus vendors have the update list, they could trace the links, block them and add detection routines for all those files. But they would only have a list and still wouldn’t figure out the source links leading to the bankers. This would be difficult because once the Trojan downloads the banker from the first list, the Trojan automatically deletes itself, wiping any trace of its existence.

STORY CONTINUES BELOW THIS AD

Attackers go through great lengths to put together such attacks. But making the entire process so complicated has a lot of benefits: first, they prevent law enforcement from tracing the malware to them. Second, they defend their assets - after all, writing a Banker Trojan is not that easy.

An antivirus vendor could destroy their work in a couple of seconds by adding signatures directly to their malware. Packers and update mechanisms allow them to circumvent generic signatures. And in case this still happens, they would only need to change the packer to be able to re-use the same piece of malware. Should the update locations be identified, it is still not a problem for crooks, since they haven’t hosted malware on their servers, but on compromised legit sites that can easily be replaced by other legit web locations.

The banker Trojan feeds users with a login form and asks them to fill it in. The data entered by the unwary clients is intercepted by crooks and sent to a C&C server to be later on be used in other malicious campaigns. The C&C server tells the infected computers apart by names, which act as unique identifiers.

STORY CONTINUES BELOW THIS AD

Bitdefender’s Advice

To avoid this kind of threat, install a good anti-virus solution and keep it updated at all times. Never install just any software application suggested in a pop-up, especially if you haven’t searched for it.

Tags
Trojan AntiVirus Web applications Mousetrap
End of Article
Written by FP Archives

see more

Latest News
Find us on YouTube
Subscribe
End of Article

Top Stories

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Who is CP Radhakrishnan, India's next vice-president?

Who is CP Radhakrishnan, India's next vice-president?

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Who is CP Radhakrishnan, India's next vice-president?

Who is CP Radhakrishnan, India's next vice-president?

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Top Shows

Vantage Firstpost America Firstpost Africa First Sports
Latest News About Firstpost
Most Searched Categories
  • Web Stories
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Tech/Auto
  • Entertainment
  • IPL 2025
NETWORK18 SITES
  • News18
  • Money Control
  • CNBC TV18
  • Forbes India
  • Advertise with us
  • Sitemap
Firstpost Logo

is on YouTube

Subscribe Now

Copyright @ 2024. Firstpost - All Rights Reserved

About Us Contact Us Privacy Policy Cookie Policy Terms Of Use
Home Video Shorts Live TV