Zitmo trojan for Android defeats two-factor authentication

Posted by   Virus Bulletin on   Jul 11, 2011

Malware intercepts TANs sent via SMS.

A new variant of the Zitmo trojan has been discovered that infects mobile devices running the Android platform and which intercepts SMS messages from banks sending mobile TAN numbers, thus potentially defeating two-factor authentication.

Two-factor authentication is used by many banks to prevent a customer's online banking account being compromised by password theft. One common way for it to work is for the customer to be required to enter both their password and a 'Transaction Authentication Number' (TAN) - which is sent to their mobile device via SMS - in order to complete a transaction. This is considered to be more secure as it is deemed unlikely that criminals would be able both to steal passwords and have access to the user's mobile device.

However, it is certainly not impossible - as the Zitmo trojan (first discovered in September 2010 for Symbian devices) shows. The trojan co-operates with the ZeuS crime kit (Zitmo stands for 'Zeus In The MObile'): when a user who is infected with ZeuS visits one of a number of particular websites, code is injected into the session, prompting the user to enter their mobile number as well as the model of the device. An SMS is then sent to that number with a link to the malicious application, which is a Zitmo variant targeting that particular operating system.

The combination of ZeuS, which steals the user's login credentials for the online banking system, and Zitmo, which intercepts mobile TANs, gives the criminals effective control of the user's bank account.

Two-factor authentication should still be a minimum requirement for online banking, but neither banks nor their customers should assume that this makes the systems undefeatable.

More at Fortinet's blog here and at CSIS;'s blog here. Fortinet's Axelle Apvrille and Kyle Yang wrote a two-part analysis of Zitmo for the March and April editions of Virus Bulletin (subscription required).

Axelle Apvrille will give a presentation on analysing mobile malware at VB2011 later this year. The conference takes place 5-7 October in Barcelona. Registration for the event is now open.

Posted on 11 July 2011 by Virus Bulletin

twitter.png
fb.png
linkedin.png
hackernews.png
reddit.png

 

Latest posts:

VB2020 localhost call for last minute papers: a unique opportunity

Why VB2020 localhost presents a unique opportunity for you to share your research with security experts around the globe.

VB2020 localhost call for last-minute papers now open!

The call for last-minute papers for VB2020 localhost is now open. Submit before 17 August to have your paper considered for one of the nine slots reserved for 'hot' research!

Announcing... VB2020 localhost

Announcing VB2020 localhost: the carbon neutral, budget neutral VB conference!

VB2019 paper: APT cases exploiting vulnerabilities in region-specific software

At VB2019, JPCERT/CC's Shusei Tomonaga and Tomoaki Tani presented a paper on attacks that exploit vulnerabilities in software used only in Japan, using malware that is unique to Japan. Today we publish both their paper and the recording of their…

New paper: Detection of vulnerabilities in web applications by validating parameter integrity and data flow graphs

In a follow-up to a paper presented at VB2019, Prismo Systems researchers Abhishek Singh and Ramesh Mani detail algorithms that can be used to detect SQL injection in stored procedures, persistent cross-site scripting (XSS), and server‑side request…

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.