Install the app
How to install the app on iOS

Follow along with the video below to see how to install our site as a web app on your home screen.

Note: This feature may not be available in some browsers.

Information-stealing 'Vawtrak' malware evolves, becomes more evasive

NavyRet

Yes, that's really me
V I P
DW Legend
Joined
Jan 1, 1970
Messages
973,885
Reaction score
8,399
Points
201
Loc
The Pegasus Galaxy
by James Wyke on December 19, 2014

Vawtrak, as we described in detail in our recent technical paper, is a dangerous banking Trojan that is actively being updated and improved on a regular basis.

As a demonstration of this, SophosLabs has recently observed a few interesting changes made by the Vawtrak authors.

The updates are mostly about disguising where the malware connects when it "calls home" to fetch its instructions on what to do next.

Additionally, the way that Vawtrak communicates with its so-called command-and-control (C&C) servers has been adapted so that the malware's traffic looks less suspicious.

We have also observed new configuration files being deployed, and an interesting trend in the commands sent back by the C&C servers when an infected computer first checks in.

How Vawtrak stores its data: more here:
Code:
https://nakedsecurity.sophos.com/2014/12/19/information-stealing-vawtrak-malware-evolves-becomes-more-evasive/
Quite an interesting read.
 
Back
Top