The Tech Herald

Zeus Trojan moving past anti-Virus protections

by Steve Ragan - Sep 17 2009, 21:15

Trusteer issued a report this week that highlights the infection rate of the Zeus family of Malware, which targets banking related information. Interestingly enough, when Trusteer sampled 10,000 users of their Rapport browser security service infected by Zeus, the Malware bypassed up-to-date anti-Virus protections the majority of the time.

“When we set out to measure the efficiency of antivirus products in the wild against Zeus, we had no idea what kind of results we would get,” said Amit Klein, CTO of Trusteer and head of the company’s research organization.

The Zeus family of Malware is the number one botnet online, with 3.6 million PC infected in the U.S. alone, Trusteer said. The Malware will infect a system and wait until the user accesses one of the predefined banking URLs listed in the Malware code. Once the site is accessed, the login information is sent to the criminals for later processing.

Zeus can also modify, in a user’s browser, the genuine web pages from a bank’s web servers to ask for personal information, such as payment card number and PIN, one time passwords, etc.

The raw data collected from the 10,000 users came from just one single day in September, and showed that 32-percent were not using anti-Virus protection, 6-percent were using it but it was out of date, and 71-percent were using anti-Virus with current updates applied.

When it came to Zeus infected systems, 31-percent were lacking anti-Virus protections entirely, 14-percent had some anti-Virus protection, but it was out of date, and the majority, 55-percent, were not only using anti-Virus software, but it was current.

“The findings, that up-to-date anti-virus programs were only effective at blocking Zeus infections 23 percent of the time, are disturbing. This is bad news for consumers and banks, since the vast majority of Zeus infections are going unnoticed,” Klein added.

With all the focus as of late, on pro-active anti-Virus protections and constantly updated signatures, the idea that Zeus was able to get past anti-Virus protection measures is concerning. How is it that with all the recent hype over community-based, cloud-leveraging, instant signature offering, and security technology pushed by the top five security vendors, almost 69-percent failed to detect Zeus?

We don’t know the vendors who were used for anti-Virus protection, nor what the version of the software was. Trusteer didn’t offer this in their report, likely because they couldn’t collect this data.

Pro-active protections are where things are heading. Faster and smaller updates, global threat detection networks linked to the client software – either on their own or thanks to an opt-in community – are designed for just this reason.

Signatures alone will not help detect Trojan’s like Zeus where there are countless variants. However, the data from Trusteer shows that the developing pro-active technology, while eventually becoming an important layer of defense, has an uphill battle ahead of it, and that it has quite some way to go before it is seriously effective.

The entire Trusteer report is online here.

 

Around the Web

Comment on this Story

comments powered by Disqus

From Autosaur.com

World’s first flat-pack truck the OX could help Africa

A flat-pack truck which can be put together by anyone in just half a day has been invented to help people living in remote places in Africa and other parts of the developing world. The OX is shipped in pieces but can be assembled with just three people in 11.5hours — and they need no [...]

The post World’s first flat-pack truck the OX could help Africa appeared first on Autosaur.

Nissan 370Z Nismo to rock the Gumball 3000 rally

The Nissan 370Z Nismo will be one of the cars in the 2013 Gumball 3000 rally where  â€” as the guys from TV show Jackass put it — “filthy stinking rich” people drive super-expensive cars 3,000 miles through 13 countries across Europe. The car, above, will be driven by a team from publishing and production [...]

The post Nissan 370Z Nismo to rock the Gumball 3000 rally appeared first on Autosaur.

#MyTurnToJag and Playboy: How Jaguar targets men

Jaguar has launched a new Twitter campaign called #MyTurnToJag to advertise its new F-Type â€” as well as teaming up with men’s magazine PLAYBOY. The #MyTurnToJag competition gives members of the public the chance to drive one of their new sports cars. And it comes after the firm helped announce Raquel Pomplun, left, as Playboy’s Playmate of [...]

The post #MyTurnToJag and Playboy: How Jaguar targets men appeared first on Autosaur.