Warning about a new phishing trojan line

Security experts have discovered a new trojan using a different communication procedure than other types of malware to send data to avoid detection.

The "unnamed" trojan sends stolen information back to spreaders through ICMP (Internet Control Message Protocol) procedures instead of email or HTTP procedures like other types of malware.

After successfully infecting the system, the trojan will impersonate an Internet Explorer Browser Helper Object (BHO) object and wait to steal the user's sensitive information when they enter the forms on the forms. webpage.

Warning about a new phishing trojan line Picture 1 And instead of sending data through an email path or HTTP POST, the trojan encodes the stolen data and uses a simple XOR algorithm before putting the data into the PING ICMP datagram session. to send.

In the eyes of network administrators and data filtering devices, ICMP packets appear to be legitimate packets. However, it is in fact that the personal information of the user is encrypted. Trojans will take those packets and decrypt them from a remote server. They will get what they want.

This is the first type of trojan to use this procedure to send data. It is a proof that malicious software is becoming more and more dangerous.

Hoang Dung

5 ★ | 1 Vote

May be interested

  • A fake trojan appears Microsoft WordA fake trojan appears Microsoft Word
    security experts are now warning users of a new trojan hidden in microsoft word files that are spreading widely through a spam campaign. the kukudro-a trojan often falsely provides information about property
  • What is Spear Phishing?What is Spear Phishing?
    you may have encountered spear phishing. when using this technique, cyber criminals will send you a message from an audience you know, asking you to provide your personal information.
  • Microsoft warns of phishing campaigns targeting Outlook Web App and Office 365 usersMicrosoft warns of phishing campaigns targeting Outlook Web App and Office 365 users
    microsoft security experts issue an important warning about an ongoing large-scale phishing, targeting outlook web app (owa) services and office 365.
  • What is a Trojan? How to avoid trojan attack?What is a Trojan?  How to avoid trojan attack?
    a trojan is not a virus, but its severity and impact are not different from viruses.
  • Trojan forged Microsoft security warningsTrojan forged Microsoft security warnings
    a spam attack campaign impersonating microsoft's security warning message has just been booted by hackers with the goal of tricking users into downloading and installing a dangerous trojan.
  • 10 investment scam warning signs you need to know10 investment scam warning signs you need to know
    there are a few signs that may warn of the instability of an investment plan if you take the time to focus and learn about what's happening. please refer to the 10 investment scam signals you need to know below!
  • Appeared fake Google Toolbar trojansAppeared fake Google Toolbar trojans
    uk-based surfcontrol has issued a warning about the emergence of a new trojan forging the latest version of google toolbar. the trojan is spread primarily by a fake email path sent by a leading search provider.
  • Trojans steal 100,000 personally identifiable informationTrojans steal 100,000 personally identifiable information
    security experts are warning a kind of data theft trojan through online advertising on job sites. most recently, the prg trojan has taken over 100,000 personally identifiable information.
  • 5 signs to identify phishing websites5 signs to identify phishing websites
    when it comes to online security, there's one age-old problem: phishing. many people receive phishing content through email or social media platforms.
  • Malware 'crawls' to hide the barrierMalware 'crawls' to hide the barrier
    a trojan horse program has been designed to hurt machines that use microsoft windows' encrypted file system. the trojan will 'crawl' into the payload of the system and hide the protection program - warning by a researcher.