VB2016 video: Last-minute paper: Malicious proxy auto-configs: an easy way to harvest banking credentials

Posted by   Martijn Grooten on   May 30, 2017

"Much media attention is given to imminent and visible threats, like ransomware. Other threats remain under the radar and often go unnoticed." This part of Jaromír Horejší and Jan Širmer's VB2016 abstract is perhaps even more relevant today than it was in September 2016, when it was written.

Despite the seriousness of WannaCry, there are many other threats that users face, and banking trojans are one of them. In their VB2016 last-minute presentation, Avast researchers Jaromír and Jan looked at Retefe, a trojan that has targeted banks in several European countries and used malicious proxy auto-config files (combined with a rogue root certificate) to redirect users' traffic to a server controlled by the attackers, thus allowing them to stealthily perform man-in-the-middle attacks.

This method isn't new (Kaspersky Lab researchers Fabio Assolini and Andrey Makhnutin spoke about it at VB2013), but remains a popular way for banking malware to empty victims' accounts.

horejsisimrerpacvb2016.png

The video of Jaromír and Jan's presentation is now available to watch on our YouTube channel.

On the subject of banking trojans, at VB2017 in Madrid, ESET researchers Peter Kalnai and Michal Poslusny will guide the audience through the attack points in browsers that are being taken advantage of by some of the major banking trojans in the wild.

VB2017 will take place in Madrid, 4-6 October 2017. Register now for an Early Bird discount!

twitter.png
fb.png
linkedin.png
googleplus.png
reddit.png

 

Latest posts:

Firefox 59 to make it a lot harder to use data URIs in phishing attacks

Firefox developer Mozilla has announced that, as of version 59 of the browser, many kinds of data URIs, which provide a way to create "domainless web content", will not be rendered in the browser, thus making this trick - used in various phishing…

Standalone product test: FireEye Endpoint

Virus Bulletin ran a standalone test on FireEye's Endpoint Security solution.

VB2017 video: Consequences of bad security in health care

Jelena Milosevic, a nurse with a passion for IT security, is uniquely placed to witness poor security practices in the health care sector, and to fully understand the consequences. Today, we publish the recording of a presentation given by Jelena at…

Vulnerabilities play only a tiny role in the security risks that come with mobile phones

Both bad news (all devices were pwnd) and good news (pwning is increasingly difficult) came from the most recent mobile Pwn2Own competition. But the practical security risks that come with using mobile phones have little to do with vulnerabilities.

VB2017 paper: The (testing) world turned upside down

At VB2017 in Madrid, industry veteran and ESET Senior Research Fellow David Harley presented a paper on the state of security software testing. Today we publish David's paper in both HTML and PDF format.