Cybercriminals have consistently found ways to undermine online banking
security measures the moment they are improved or updated, which makes
securing financial networks a continuously evolving and especially difficult task.
If a bank uses a simple authentication scheme involving only a user name
and a password, keyloggers are used to gain access. Banks that use onetime password (OTP) systems are injected with ATS scripts that hide illegal
transactions. Like ATSs, Browser Helper Objects (BHOs) are also used against
complex systems that implement two- or three-factor authentication. These
techniques show the ingenuity of cybercriminals, who match every advance in
online bank security with an equally innovative means to evade it.
Most sophisticated crimeware kits use
popular online banking Trojans that
are offshoots of the BANCOS family
of crime kits. BANCOS malware often
function like rootkits by removing
security components in target
computers used to access bank
accounts. Although these kits have
been prevalent for years, they were
only considered a significant threat in
the Americas and the Caribbean
because of unpatched security
systems and low levels of awareness.6
TSPY_QHOST.AFG pretends to be a
component of a legitimate banking site plug-in
to get into victims’ computers.
TSPY_QHOST.AFG is an example of a BANCOS Trojan.7 Unlike most strains
it does not only change an infected computer’s HOSTS file, it also employs
uniquely advanced functions to evade anti-malware detection.
TSPY_QHOST.AFG encrypts strings to evade detection and complicate analysis.
Cybercriminals in the Americas and the Caribbean also use Domain Name
System (DNS) changers and remote access Trojans (RATs). They change
proxy configurations and/or add information to the HOSTS file to breach online
banking systems.
The previously discussed tools are most frequently delivered by embedding
malicious links in spam or convincing phishing websites.
6
7
http://blog.trendmicro.com/trendlabs-security-intelligence/new-crimeware-in-bancos-paradise/
http://about-threats.trendmicro.com/malware.aspx?language=au&name=TSPY_QHOST.AFG
PAGE 13 | Latin American and Caribbean Cybersecurity Trends and Government Responses