New variant of Zeus banking trojan concealed in JPG images

Tuesday, February 18th, 2014

A new variant of the nefarious Zeus banking trojan – dubbed ZeusVM – is concealed in JPG image files, according to the collaborative findings of Jerome Segura, senior security researcher with Malwarebytes, and French security researcher Xylitol. The act is known as steganography – concealing messages or images in other messages or images. In ...

Java-based malware hits Windows, Mac and Linux

Wednesday, January 29th, 2014

Kaspersky Lab researchers have recently analysed a piece of malware that works well on all three of the most popular computer operating systems - the only thing that it needs to compromise targeted computers is for them to run a flawed version of Java. The Trojan is written wholly in Java, and exploits ...

New Windows malware tries to infect Android devices connected to PCs

Friday, January 24th, 2014

A new computer Trojan program attempts to install mobile banking malware on Android devices when they're connected to infected PCs, according to researchers from Symantec. This method of targeting Android devices is unusual, since mobile attackers prefer social engineering and fake apps hosted on third-party app stores to distribute Android malware. "We've ...

Virus can attack ‘any bank anywhere’

Friday, November 29th, 2013

Kaspersky Lab has recorded several thousand attempts to infect computers used for online banking with a malicious programme that its creators claim can attack “any bank in any country”. The Neverquest Trojan banker supports just about every possible trick used to bypass online banking security systems: web injection, remote system access, ...

PHP.net compromised to serve malware

Friday, October 25th, 2013

On Thursday, Google's Safe Browsing service began warning visitors to php.net that the website was discovered serving malware. Initially, most people and PHP maintainers thought that it was a false positive, but subsequent investigation confirmed that some of the project's servers did get compromised. The hackers succeeded in injecting malicious JavaScript code (userprefs.js) ...