-
New Labs report
Read more how the Zeus trojan has been updated to undermine tracking and detection -
FFIEC guidance
How TrustDefender helps -
TD Pro for Mac
TrustDefender launches TrustDefender Pro for Mac to protect MacOS X users from a growing list of online threats. -
Safety of online business
TrustDefender helps to secure the future of e-commerce. -
New Security Management
Increasing company's preparedness for online fraudulent activity. -
TrustDefender enters next phase of growth
Find out more. -
Myth vs Reality
Apple's approach to defeating malware attacks. Myths vs reality. -
TrustDefender Predictions
The year of malware attacks. -
HTML and JavaScript injection
In-depth analysis into how the malware infiltrates websites and the details of its operation. -
eCrime Summit Abu Dhabi
TrustDefender continues its drive into the Middle East market exhibiting at eCrime Summit Abu Dhabi. -
Matt Sheehan
TrustDefender appoints Matthew Sheehan to drive aggressive sales growth strategy in Australia and New Zealand -
InfoSight Partnership
TrustDefender partners with InfoSight, Inc., to address need for effective online transaction security in the US -
GBM Partnership
TrustDefender and Gulf Business Machines (GBM) have announced their joint partnership. -
Gozi Trojan
TrustDefender Labs report has alarmingly discovered another variant of the Gozi Trojan with a 0% detection rate. -
Tim Thompson
TrustDefender appoints security and technology industry expert, Tim Thompson to lead Sales and Operations. -
Urgent Announcement
TrustDefender not associated with rogue AV software that is being distributed under the same name. -
The New Zeus
TrustDefender reveals true threat of new Trojan Carberp– the new Zeus! -
GITEX Technology Week
Showcasing their unique risk-based online transaction security solution at GITEX Technology Week in Dubai. -
25th Anniversary
Leading security expert Andreas Baumhof to speak at 25th Anniversary of Security 2010 Conference. -
Las Vegas Credit Union Conference
Showcasing the world’s first real-time customer endpoint risk assessment and protection for online transactions in Las Vegas. -
New Vice President
Alex Shipp appointed Vice President of Advanced Threat Research at TrustDefender -
Secure Online Identities
TrustDefender comments on the US Government’s draft plan to secure online identities. -
National Cyber Security Week 2010
TrustDefender supports National Cyber Security Week 2010 and encourages Australians to take responsibility for online security. -
Trust Defender raises $16m
TrustDefender bringing it's ‘revolutionary real-time risk based online transaction security solutions’ to a market... -
Growing Operations
TrustDefender announces North American operations led by Joseph McGrath
TrustDefender reveals true threat of new Trojan Carberp– the new Zeus!
Written by Andreas Baumhof Friday, 08 October 2010 01:00

Leading online transaction security provider, TrustDefender has analysed the latest new transactional Trojan Carberp, (pronounced Car-ber-‘P’), which is already gaining momentum with cyber criminals in Europe and the US. Financial institutions and enterprises should be wary of Carberp as it is challenging the highly successful transactional Trojans; Zeus, Mebroot and Silentbanker to become a leading malware security threat.
TrustDefender Labs (the research and development division of TrustDefender) has discovered the potential impacts and risks of this new Trojan. While Zeus has been the leading class of malware for security attacks throughout the last 18 months, there are a number of new players entering the market with an extensive new feature-set and distribution network challenging existing Trojan detection software.
Online Security expert and CTO of TrustDefender, Andreas Baumhof comments; "This particular Trojan appears to be purpose built and has evolved in sophistication at a rapid rate. TrustDefender anticipates Carberp will further develop and could morph into a problematic threat from a financial, political and personal perspective. This demonstrates how quickly the bad guys are innovating new sophisticated threats."
Carberp was first seen in May 2010, however most recently TrustDefender experts have witnessed the increasing sophistication of the Trojan, which is evolving at a very fast rate. Carberp is a promising challenger to Zeus and potentially provides a new class of Trojan for cyber criminals to use.
Why should we be worried about Carberp?
- Ability to disable other Trojans so it does not interfere with its attack and more importantly does not send stolen information to the competition
- Ability to run as a non-administrator
- Ability to infect Windows XP, Windows Vista and Windows 7, which only few Trojans can do. The Browser Hooking also works for Firefox in various versions but still not yet Chrome.
- Sophisticated browser hooking/installation to fully control all internet traffic (including HTTPS with EV-SSL) and the entire internet session
- It will not make any changes to the registry (only in memory modifications)
- Stolen data is transmitted in real-time to a Trojan’s ‘Command and Control’ (C&C) Server
- Carberp also has a configuration file system where it can inject arbitrary HTML into any website
- Ability to inject dynamically HTML overlays into any banking session, similarly to Zeus, Gozi and Spyeye, with the aim to work around dynamic authentication schemes (such as 2fa authentication)
Andreas Baumhof continues "The evolution of Trojans such as Carberp highlights that the malware problem is here to stay and will only get worse with malware reaching out to new areas such as Windows 7, Apple Mac and mobile devices. This highlights the need for financial institutions and enterprises to provide appropriate security for their users so the end user’s device is fully protected. This obviously also applies for cloud based applications. While Trojans such as Zeus and Mebroot are successful and high profile; the ‘bad guys’ obviously wish to stay under the radar and with new malware and configuration files they are able to continue to infiltrate in new ways."

