Defeating mTANs for profit
Axelle Apvrille, Kyle Yang
ShmooCon, January 2011
Zeus (aka Zbot): background
•
It’s a crimeware kit, sold in the underground market
•
Designed to steal banking information
•
There are several Zeus botnets, not only one
What’s new for Zitmo’s propagation?
•
Not ’much’, because fully configurable
•
Uses a different RC4 key to decrypt the configuration file
•
Targets Spanish banks, injects Javascript into those URLs
Defeating mTANs for profit - A. Apvrille, K. Yang 4/23