-
New Labs report
Read more how the Zeus trojan has been updated to undermine tracking and detection -
FFIEC guidance
How TrustDefender helps -
TD Pro for Mac
TrustDefender launches TrustDefender Pro for Mac to protect MacOS X users from a growing list of online threats. -
Safety of online business
TrustDefender helps to secure the future of e-commerce. -
New Security Management
Increasing company's preparedness for online fraudulent activity. -
TrustDefender enters next phase of growth
Find out more. -
Myth vs Reality
Apple's approach to defeating malware attacks. Myths vs reality. -
TrustDefender Predictions
The year of malware attacks. -
HTML and JavaScript injection
In-depth analysis into how the malware infiltrates websites and the details of its operation. -
eCrime Summit Abu Dhabi
TrustDefender continues its drive into the Middle East market exhibiting at eCrime Summit Abu Dhabi. -
Matt Sheehan
TrustDefender appoints Matthew Sheehan to drive aggressive sales growth strategy in Australia and New Zealand -
InfoSight Partnership
TrustDefender partners with InfoSight, Inc., to address need for effective online transaction security in the US -
GBM Partnership
TrustDefender and Gulf Business Machines (GBM) have announced their joint partnership. -
Gozi Trojan
TrustDefender Labs report has alarmingly discovered another variant of the Gozi Trojan with a 0% detection rate. -
Tim Thompson
TrustDefender appoints security and technology industry expert, Tim Thompson to lead Sales and Operations. -
Urgent Announcement
TrustDefender not associated with rogue AV software that is being distributed under the same name. -
The New Zeus
TrustDefender reveals true threat of new Trojan Carberp– the new Zeus! -
GITEX Technology Week
Showcasing their unique risk-based online transaction security solution at GITEX Technology Week in Dubai. -
25th Anniversary
Leading security expert Andreas Baumhof to speak at 25th Anniversary of Security 2010 Conference. -
Las Vegas Credit Union Conference
Showcasing the world’s first real-time customer endpoint risk assessment and protection for online transactions in Las Vegas. -
New Vice President
Alex Shipp appointed Vice President of Advanced Threat Research at TrustDefender -
Secure Online Identities
TrustDefender comments on the US Government’s draft plan to secure online identities. -
National Cyber Security Week 2010
TrustDefender supports National Cyber Security Week 2010 and encourages Australians to take responsibility for online security. -
Trust Defender raises $16m
TrustDefender bringing it's ‘revolutionary real-time risk based online transaction security solutions’ to a market... -
Growing Operations
TrustDefender announces North American operations led by Joseph McGrath
Gozi Trojan - king of evasion continues to avoid sophisticated detection
Written by Andreas Baumhof Monday, 08 November 2010 14:36

The recent TrustDefender Labs report has alarmingly discovered another variant of the Gozi Trojan with a 0% detection rate. TrustDefender Labs has recently re-analysed the Trojan Gozi, (pronounced goh'-zee), which has been showing fraudulent attacks since 2007. Their research highlights how the Gozi Trojan is very professional, efficient and attacks financial institutions worldwide by managing to stay under the radar and remain undetectable. By targeting specific financial institutions (mainly business and corporate banking in the US) Gozi endeavours not to attract industry attention with this approach. While everybody is talking about Zeus, Gozi can do its dirty work.
During the TrustDefender Labs tests the Gozi Trojan was invisible to all leading anti-virus software, allowing it to infiltrate and attack user’s systems and browsers. The new Gozi variant has many of the same characteristics of its predecessor (researched 12 months ago) however, is showing increasing sophistication in HTML injection compared to other Trojans. Gozi perpetrators have been successfully evading signature patterns so consistently that the evolution of the Trojan has been relatively unknown. This highlights the potential risks and impacts of attacks on financial institutions, businesses and individuals whilst staying predominantly undetectable to any anti-virus software.
Online Security expert and CTO of TrustDefender, Andreas Baumhof comments; “Gozi is unbelievably good at staying under the radar from an infection point of view, but this particular sample also used SSL and HTTPS against the good guys. Typically designed to protect us, the fraudulent use of HTTPS helps them to stay virtually invisible for their C&C server connection. Alarmingly we are coming across an increasing number of Trojans that are using SSL and HTTPS to cover their tracks. The other thing that impressed us was the extensive client-side logic to circumvent even Two-Factor Authentication. Unfortunately this is becoming more common as we see similar techniques with Trojans such as Zeus, Spyeye, Carberp.”
Why should we be worried about Gozi?
- Gozi is one of the most sophisticated Trojans out there with an impressive feature set.
- Gozi can use encrypted HTTPS connection for its C&C server communication with a valid certificate meaning it can evade detection.
- Traditional anti-virus software is unable to detect the Gozi Trojan
- Gozi features an extensive client side logic (in JavaScript) to be able to work with many different banking websites and also allowing it to steal static information (such as maiden name) and also dynamic password schemes (such as Two-Factor Authentication and One-Time-Passwords). This is similar to Zeus, Spyeye, Carberp and Silon
- Gozi enables real time account takeover that even works with Two-Factor Authentication.

