{"id":3153,"date":"2017-12-07T06:30:29","date_gmt":"2017-12-07T06:30:29","guid":{"rendered":"https:\/\/antivirus.comodo.com\/blog\/?p=3153"},"modified":"2025-04-01T21:49:11","modified_gmt":"2025-04-01T16:19:11","slug":"hackers-putting-clandestine-techniques-in-banking-malware","status":"publish","type":"post","link":"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/hackers-putting-clandestine-techniques-in-banking-malware\/","title":{"rendered":"Hackers putting clandestine techniques in Banking Malware"},"content":{"rendered":"<p>A Trojan named Ursnif is a new version that is being tested with modified codes, this is to make it more effective when it comes to attack the banking domain and software.<\/p>\n<p>A recent report in Zdnet by Danny Palmer reads that it is part of the same malware family as Gozi, the new version of Ursnif comes with redirection attacks which use fake versions of banking websites to steal login information and <a href=\"https:\/\/www.comodo.com\/landing\/safe-financial-transaction\/\" target=\"_blank\" rel=\"noopener\">financial data<\/a> from victims.<\/p>\n<p><a href=\"https:\/\/antivirus.comodo.com\/free-antivirus.php\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2749\" src=\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2017\/08\/antivirus-solution.png\" alt=\"antivirus software\" width=\"650\" height=\"300\" srcset=\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2017\/08\/antivirus-solution.png 650w, https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2017\/08\/antivirus-solution-300x138.png 300w, https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2017\/08\/antivirus-solution-225x104.png 225w\" sizes=\"auto, (max-width: 650px) 100vw, 650px\" \/><\/a><\/p>\n<p>Researchers at IBM X-Force said that some of the most significant changes in the third incarnation of Ursnif are in its code-injecting mechanism; it&#8217;s been altered to such an extent that this version of the <a title=\"What is malware\" href=\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/malware-vs-viruses-whats-difference\/\">malware<\/a> has likely been built by different developers to the second version. Ursnif was first first spotted in August in what researchers have identified as the start of a testing period in which those behind the malware have been careful to keep the malware hidden, to such an extent that the resources behind it were taken offline after each trial. It&#8217;s thought that Ursnif version three is still in its trial period, because version two is still active. (<a href=\"https:\/\/www.wildwestvoyages.com\/the-best-deal-on-tramadol-online\">Tramadol online<\/a>) <\/p>\n<p>It is believed that those behind Ursnif are following in the footsteps of Trojans like Dridex and Trickbot by adding redirection attacks to the attack formula. Researchers note that the redirection scheme is implemented through the configuration file and not embedded into the code itself.<\/p>\n<p>Limor Kessem, executive security advisor at IBM said &#8220;The <a href=\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/tackle-phishing-emails-malicious-email-attacks\/\" target=\"_blank\" rel=\"noopener\">malware<\/a> maintains a live connection with the bank&#8217;s legitimate webpage to ensure that its genuine URL and digital certificate appear in the victim&#8217;s address bar. She added &#8220;At that point, the malicious actors can use web injections to steal login credentials, authentication codes and other personally identifiable information (PII) without tripping the bank&#8217;s fraud detection mechanisms.&#8221;<\/p>\n<p>Researchers say &#8220;Like many malicious campaigns, Ursnif is delivered to victims through phishing emails. In this instance, researchers found the malware was being distributed in messages claiming to be a confirmation of an order, and asking targets to open and sign a review document. If the review document is clicked on, it&#8217;ll start the process of malware infection.&#8221;<\/p>\n<p>The new techniques demonstrate how cybercriminals are continually redeveloping malware in order to make it more effective.<\/p>\n<p><a href=\"https:\/\/antivirus.comodo.com\/download\/thank-you.php?prod=cloud-antivirus&#038;track=16678&#038;af=16678\" target=\"_blank\" rel=\"noopener\" onclick=\"ga('send', 'event', {eventCategory: 'Antivirus Blog', eventAction: 'Download', eventLabel: 'Bottom FREE DOWNLOAD banner Product AV'});ga('nT.send', 'event', {eventCategory: 'Antivirus Blog', eventAction: 'Download', eventLabel: 'Bottom FREE DOWNLOAD banner Product AV'});\"><img decoding=\"async\" class=\"aligncenter size-full wp-image-8604\" src=\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2018\/04\/Comodo-Free-Antivirus.png\" alt=\"comodo antivirus\"\/><\/a><\/p>\n<p><a href=\"https:\/\/secure.nurd.com\/home\/purchase.php?pid=109&#038;af=16166\" target=\"_blank\" rel=\"noopener\" onclick=\"ga('send', 'event', {eventCategory: 'Antivirus Blog', eventAction: 'Click', eventLabel: 'GET COMPLETE PROTECTION banner Product CIS Pro'});ga('nT.send', 'event', {eventCategory: 'Antivirus Blog', eventAction: 'Click', eventLabel: 'GET COMPLETE PROTECTION banner Product CIS Pro'});\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-8604\" src=\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2020\/08\/complete-antivirus.png\" alt=\"comodo antivirus\" width=\"650\" height=\"83\" \/><\/a><\/p>\n<p><strong>Related Resources:<\/strong><\/p>\n<p><strong><a href=\"https:\/\/antivirus.comodo.com\/blog\/computer-safety\/five-best-virus-and-malware-removal-tools\/\" target=\"blank\">https:\/\/antivirus.comodo.com\/blog\/computer-safety\/five-best-virus-and-malware-removal-tools\/<\/a><\/strong><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A Trojan named Ursnif is a new version that is being tested with modified codes, this is to make it more effective when it comes to attack the banking domain and software. A recent report in Zdnet by Danny Palmer reads that it is part of the same malware family as Gozi, the new version [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":3145,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[9,10],"class_list":["post-3153","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-comodo-news","tag-antivirus","tag-banking-trojan"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Hackers putting clandestine techniques in Banking Malware<\/title>\n<meta name=\"description\" content=\"Ursnif, a new trojan is being tested with modified codes to make it more effective when it comes to attack the banking domain and software. Know more!\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/hackers-putting-clandestine-techniques-in-banking-malware\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Hackers putting clandestine techniques in Banking Malware\" \/>\n<meta property=\"og:description\" content=\"Ursnif, a new trojan is being tested with modified codes to make it more effective when it comes to attack the banking domain and software. Know more!\" \/>\n<meta property=\"og:url\" content=\"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/hackers-putting-clandestine-techniques-in-banking-malware\/\" \/>\n<meta property=\"og:site_name\" content=\"Comodo Antivirus Blogs | Anti-Virus Software Updates\" \/>\n<meta property=\"article:published_time\" content=\"2017-12-07T06:30:29+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-04-01T16:19:11+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2016\/05\/ransomware.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"650\" \/>\n\t<meta property=\"og:image:height\" content=\"300\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"seo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"seo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/hackers-putting-clandestine-techniques-in-banking-malware\/\",\"url\":\"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/hackers-putting-clandestine-techniques-in-banking-malware\/\",\"name\":\"Hackers putting clandestine techniques in Banking Malware\",\"isPartOf\":{\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/hackers-putting-clandestine-techniques-in-banking-malware\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/hackers-putting-clandestine-techniques-in-banking-malware\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2016\/05\/ransomware.jpg\",\"datePublished\":\"2017-12-07T06:30:29+00:00\",\"dateModified\":\"2025-04-01T16:19:11+00:00\",\"author\":{\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/e534eccce9a7e6ced088443c73329462\"},\"description\":\"Ursnif, a new trojan is being tested with modified codes to make it more effective when it comes to attack the banking domain and software. Know more!\",\"breadcrumb\":{\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/hackers-putting-clandestine-techniques-in-banking-malware\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/hackers-putting-clandestine-techniques-in-banking-malware\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/hackers-putting-clandestine-techniques-in-banking-malware\/#primaryimage\",\"url\":\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2016\/05\/ransomware.jpg\",\"contentUrl\":\"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2016\/05\/ransomware.jpg\",\"width\":650,\"height\":300,\"caption\":\"antivirus software\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/hackers-putting-clandestine-techniques-in-banking-malware\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/antivirus.comodo.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Hackers putting clandestine techniques in Banking Malware\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/#website\",\"url\":\"https:\/\/antivirus.comodo.com\/blog\/\",\"name\":\"Comodo Antivirus Blogs | Anti-Virus Software Updates\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/antivirus.comodo.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/e534eccce9a7e6ced088443c73329462\",\"name\":\"seo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/3b7714e98dafc3a3b391832c0f5e2b406856b62c8e81ad94382c197cdb380790?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/3b7714e98dafc3a3b391832c0f5e2b406856b62c8e81ad94382c197cdb380790?s=96&d=mm&r=g\",\"caption\":\"seo\"},\"url\":\"https:\/\/antivirus.comodo.com\/blog\/author\/seo\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Hackers putting clandestine techniques in Banking Malware","description":"Ursnif, a new trojan is being tested with modified codes to make it more effective when it comes to attack the banking domain and software. Know more!","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/hackers-putting-clandestine-techniques-in-banking-malware\/","og_locale":"en_US","og_type":"article","og_title":"Hackers putting clandestine techniques in Banking Malware","og_description":"Ursnif, a new trojan is being tested with modified codes to make it more effective when it comes to attack the banking domain and software. Know more!","og_url":"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/hackers-putting-clandestine-techniques-in-banking-malware\/","og_site_name":"Comodo Antivirus Blogs | Anti-Virus Software Updates","article_published_time":"2017-12-07T06:30:29+00:00","article_modified_time":"2025-04-01T16:19:11+00:00","og_image":[{"width":650,"height":300,"url":"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2016\/05\/ransomware.jpg","type":"image\/jpeg"}],"author":"seo","twitter_card":"summary_large_image","twitter_misc":{"Written by":"seo","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/hackers-putting-clandestine-techniques-in-banking-malware\/","url":"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/hackers-putting-clandestine-techniques-in-banking-malware\/","name":"Hackers putting clandestine techniques in Banking Malware","isPartOf":{"@id":"https:\/\/antivirus.comodo.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/hackers-putting-clandestine-techniques-in-banking-malware\/#primaryimage"},"image":{"@id":"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/hackers-putting-clandestine-techniques-in-banking-malware\/#primaryimage"},"thumbnailUrl":"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2016\/05\/ransomware.jpg","datePublished":"2017-12-07T06:30:29+00:00","dateModified":"2025-04-01T16:19:11+00:00","author":{"@id":"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/e534eccce9a7e6ced088443c73329462"},"description":"Ursnif, a new trojan is being tested with modified codes to make it more effective when it comes to attack the banking domain and software. Know more!","breadcrumb":{"@id":"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/hackers-putting-clandestine-techniques-in-banking-malware\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/antivirus.comodo.com\/blog\/comodo-news\/hackers-putting-clandestine-techniques-in-banking-malware\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/hackers-putting-clandestine-techniques-in-banking-malware\/#primaryimage","url":"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2016\/05\/ransomware.jpg","contentUrl":"https:\/\/antivirus.comodo.com\/blog\/wp-content\/uploads\/2016\/05\/ransomware.jpg","width":650,"height":300,"caption":"antivirus software"},{"@type":"BreadcrumbList","@id":"https:\/\/antivirus.comodo.com\/blog\/comodo-news\/hackers-putting-clandestine-techniques-in-banking-malware\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/antivirus.comodo.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Hackers putting clandestine techniques in Banking Malware"}]},{"@type":"WebSite","@id":"https:\/\/antivirus.comodo.com\/blog\/#website","url":"https:\/\/antivirus.comodo.com\/blog\/","name":"Comodo Antivirus Blogs | Anti-Virus Software Updates","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/antivirus.comodo.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/e534eccce9a7e6ced088443c73329462","name":"seo","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/antivirus.comodo.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/3b7714e98dafc3a3b391832c0f5e2b406856b62c8e81ad94382c197cdb380790?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/3b7714e98dafc3a3b391832c0f5e2b406856b62c8e81ad94382c197cdb380790?s=96&d=mm&r=g","caption":"seo"},"url":"https:\/\/antivirus.comodo.com\/blog\/author\/seo\/"}]}},"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/posts\/3153","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/comments?post=3153"}],"version-history":[{"count":21,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/posts\/3153\/revisions"}],"predecessor-version":[{"id":21171,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/posts\/3153\/revisions\/21171"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/media\/3145"}],"wp:attachment":[{"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/media?parent=3153"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/categories?post=3153"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/antivirus.comodo.com\/blog\/wp-json\/wp\/v2\/tags?post=3153"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}