Released Crimeware Targets Business Data

Yuval Ben-Itzhak, CTO of Finjan, has warned IT managers in companies of all sizes to be on the lookout for a wave of Trojans, and to protect company IT resources and business data against this growing form of crimeware.

Ben-Itzhak's warning comes in the wake of reports of a $1,000 crimeware development kit, including a Trojan, being sold to would-be hacker criminals.

The new variant, “Prg”, researched by Finjan’s Malicious Code Research Center (MCRC) and also noted by Don Jackson of managed security specialist SecureWorks, relays sensitive data collected during employees’ online activity to hacker Web sites, using SSL-encrypted format. Finjan’s MCRC found criminals’ servers in Panama.

Jackson's research suggests that the crimeware has been modified using a Trojan development kit to listen for hacker commands on a special TCP/IP port. These commands allow the hacker to gain remote control of the compromised system. Jackson’s analysis of log files on the servers storing the stolen data found that information was coming from corporate PCs, as noted in his report.

"This trend highlights the alarming growth of crimeware toolkits being sold to criminals by hackers. Such crimeware is focusing on stealing sensitive business data and sending it back to criminals’ servers over encrypted communication channels like SSL, in order to go undetected", said Ben-Itzhak. “IT managers need to be aware of this latest evolution in crimeware, as Finjan’s research confirms that attempts to pattern malicious code and create signatures, or to categorize known malicious sites, are clearly ‘too little, too late’ when it comes to providing adequate protection to today’s dynamic and evasive Web threats. The way to detect modern malicious code is to be able to understand in real-time what the code intends to do, before it does it.”

Featured

New Products

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.

  • AC Nio

    AC Nio

    Aiphone, a leading international manufacturer of intercom, access control, and emergency communication products, has introduced the AC Nio, its access control management software, an important addition to its new line of access control solutions.

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities