by James Wyke on December 19, 2014
Vawtrak, as we described in detail in our recent technical paper, is a dangerous banking Trojan that is actively being updated and improved on a regular basis.
As a demonstration of this, SophosLabs has recently observed a few interesting changes made by the Vawtrak authors.
The updates are mostly about disguising where the malware connects when it "calls home" to fetch its instructions on what to do next.
Additionally, the way that Vawtrak communicates with its so-called command-and-control (C&C) servers has been adapted so that the malware's traffic looks less suspicious.
We have also observed new configuration files being deployed, and an interesting trend in the commands sent back by the C&C servers when an infected computer first checks in.
How Vawtrak stores its data: more here:
Quite an interesting read.
Vawtrak, as we described in detail in our recent technical paper, is a dangerous banking Trojan that is actively being updated and improved on a regular basis.
As a demonstration of this, SophosLabs has recently observed a few interesting changes made by the Vawtrak authors.
The updates are mostly about disguising where the malware connects when it "calls home" to fetch its instructions on what to do next.
Additionally, the way that Vawtrak communicates with its so-called command-and-control (C&C) servers has been adapted so that the malware's traffic looks less suspicious.
We have also observed new configuration files being deployed, and an interesting trend in the commands sent back by the C&C servers when an infected computer first checks in.
How Vawtrak stores its data: more here:
Code:
https://nakedsecurity.sophos.com/2014/12/19/information-stealing-vawtrak-malware-evolves-becomes-more-evasive/