New Version of Russian Gozi Trojan Detected

ATLANTA – Internet security providers say they have discovered a stealthier version of the Russian Trojan called Gozi that has already stolen personal financial data from more than 2,000 home PCs, including credit union and bank account numbers, as well as credit card, Social Security and online payment account numbers and passwords. The new strain of Gozi, discovered by SecureWorks, the same firm that detected the original version, is programmed to steal information from encrypted Secure Sockets Layer (SSL) streams and send the stolen information to a server in Russia. The new version, however, includes an unseen ‘packer’ that encrypts, mangles, compresses and even deletes portions of the Trojan code to evade detection by standard, signature-based antivirus programs. The new version of Gozi also has a new keystroke-logging capability for stealing data, in addition to its ability to steal data from Ssl streams. The keystroke logger appears to be activated when the user of an infected computer visits a banking web site or initiates an SSL session. The original Gozi Trojan stole more than 10,000 records from more than 30 financial institutions, including two dozen credit unions, containing information belonging to more than 5,200 PCs, companies, government agencies and law enforcement organizations before being detected.

Processing Content

For reprint and licensing requests for this article, click here.
MORE FROM AMERICAN BANKER
Load More