Beware of e-banking virus out to steal passwords

The Trojan variant virus has six aliases and may come as attachements

GN Bureau | February 11, 2015


#e banking   #trojan   #e banking virus   #banking news   #technology news  

A deadly virus with six aliases is on the prowl and most vulnerable are the e-banking users.

The Trojan variant virus, which has been named as 'Cridex' attacks and steals personal login secrets and passwords of e-banking customers.

Some of the identified aliases of this banking virus are 'Geodo', 'Dapato', 'W32/Kryptik.BVB', 'Worm.Win32.Cridex', 'PWS:Win32/Zbot' and 'Trojan.Gen.2' and can be noticed by these names when they appear online.

"It has been observed that the new variants of Cridex malware are spreading widely. Cridex is an information stealing e-banking Trojan that propagates via removable drives and targets users of online banking/social media for stealing user name, passwords among others," the Computer Emergency Response Team of India (CERT-In) said in its latest advisory to e-banking users in the country.

"Like the other major banking Trojans, the malware performs web injects into the HTML pages of financial institutions contained in the configuration file. The malware routes the users to fake banking sites for divulging user information and subsequently connects to the bank site from the victim IP address by bypassing IP reputation blocking," the agency said in its alert.

The agency said, once activated, the virus targets and steals login credentials of various banks and social networking sites like Facebook, Twitter and Instagram among others.

Steps to be taken by users

Enable firewall at desktop and gateway level; update patches and fixes of the operating system and application software; update anti-virus and anti-spyware signatures at entry points; update and install the latest updates and softwares to protect computer from viruses, Trojans; guard against social engineering attacks; opt for strong passwords with alpha numeric characters; resist temptations of opening attachments from known or unknown sources and do not download pirated software.

What is CERT-IN?

CERT-In (the Indian Computer Emergency Response Team) is a government-mandated information technology (IT) security organization. The purpose of CERT-In is to respond to computer security incidents, report on vulnerabilities and promote effective IT security practices throughout the country.

CERT-In was created by the Indian Department of Information Technology in 2004 and operates under the auspices of that department. According to the provisions of the Information Technology Amendment Act 2008, CERT-In is responsible for overseeing administration of the Act.

CERT organizations throughout the world are independent entities, although there may be coordinated activites among groups. The first CERT group was formed in the United States at Carnegie Mellon University.

Comments

 

Other News

BRICS at 20: From economic weight to global influence

This year marks 20 years of BRICS, with India set to host the grouping’s leaders’ summit this weekend. The anniversary offers an opportune moment to assess BRICS’ growing importance at a time when the effectiveness of global governance and the credibility of multilateralism are under in

Former president Ram Nath Kovind on some of his unforgettable journeys

Triumph of the Indian Republic: My Life, My Struggles By Ram Nath Kovind Rupa Publications, 400 pages, Rs 795   All our presidents so far stand out, each for a different reason. Ram Nath Kovind, the 14th president of India, from 2017 t

Uday Kotak on history, Indian economy, growth and more

Pathbreakers: How 10 Visionary Leaders Transformed India by award-winning journalists  By Sucheta Dalal and Debashis Basu Rupa Publications, 304 pages, Rs 695  

₹5,000 crore saved from suspected financial fraud

In a significant gain for citizen protection in the digital economy, the Department of Telecommunications (DoT) has helped prevent suspected cyber fraud losses of more than ₹5,000 crore through its Financial Fraud Risk Indicator (FRI) within fifteen months of its launch on May 22, 2025. This money did

Capital acquisition proposals worth Rs 1.10 lakh crore for defence forces cleared

The Defence Acquisition Council (DAC), under the chairmanship of Raksha Mantri Rajnath Singh, on Monday accorded Acceptance of Necessity (AoN), that is, in-principle administrative approval to various acquisition proposals of the defence forces at an estimated cost of about Rs 1,10,000 crore.

How Rafi, Raj Kapoor helped pave the way for a great uranium deal

There`s a certain moment in diplomacy that`s too personal to be captured in a communiqué, too small to make the front page, but more revealing than the front page. This week, prime minister Narendra Modi reached Tashkent and, amid the pomp of state visits, managed to evoke the old Bollywood tunes

Upcoming Conferences



-->

Archives

Current Issue

Opinion

Facebook Twitter Google Plus Linkedin Subscribe Newsletter

Twitter