Simple clear advice in plain English

Tilon Trojan latest malware to target UK and European banks

Sophisticated malware mutates to bypass security protection warns Trusteer

Concept image representing virus malware
Tilon trojan targeting UK and European banks

A new banking Trojan infecting PCs with a man-in-the-browser attack is extremely sophisticated and comes with "a full bag of tricks" security company Trusteer is warning.

The Tilon Trojan is able to inject itself into an "impressive list of browsers" including Internet Explorer, Firefox, Chrome, the company said. Amit Klein, Trusteers' chief technology officer, said Tilon manages to evade detection by most security software.

Read more: Security and crime news | Security advice

The victim is infected by either visiting a website that has been compromised by the criminals or via email campaigns, which entice them to infected pages. They do not have to click on anything as Tilon automatically starts to download.

It is targeting UK and European banks and will control the traffic between the browser and banking website, collecting passwords, personal details and account numbers before sending these to the command and control servers used by the criminals.

Trusteer said one of the most impressive aspects of Tilon is the breadth of evasion techniques it employs to avoid detection and scrutiny and to survive "attacks" by security products.

"Some of the evasion techniques we are aware of include Tilon installing itself as a service with a genuine-looking name. We have also seen it start a watchdog thread that monitors its service entry in the registry and its executable file on disk.

"If these are tampered with, Tilon restores them within three seconds. This mechanism resists removal by many security products," the company said.

Reader Comments

   

Add your comment

Please keep comments constructive and free from abuse of any kind and swearing. If you wish to link to a product or service online, please do so in such a way that makes it clear that it is not spam. If you are connected to any such product you should make that clear.

We may use your comments in the magazine. We may edit your comments for clarity or to remove unacceptable material. We will attribute your comments but not share your email address.

We request your email address and record your Internet Address (IP address) in order to block spam from our site. We will never share this information without your permission.

All comments are reviewed by the Computeractive Team before being published. Please bear with the slight delay this causes, you don't need to post more than once.

Click here to read our Privacy Policy

Click here to read our site Terms & Conditions

Related articles

hp-touchscreen-printer

Milicenso Trojan attacks printers

Malicious software makes printers across the world output gobbledegook

malware

Sophos warns fake Adobe upgrade contains Zeus Trojan

Attached ZIP file in emails could con people into downloading banking Trojan

Lenovo Lephone K2 Android Smartphone

Porn app hides Trojan to target Android smartphones warns F-Secure

App hides a Trojan that hijacks phones to send premium rate sms

Content Recommendation

Question & Answer

Q.Why is Windows Backup skipping files?

> Read the answer

Q.Why do my scanned documents display gibberish?

> Read the answer

Q.How can I convert MTS files to edit in Windows Movie...

> Read the answer

Best deals on the web

img

Samsung NP350E7C-A04UK

£349.99- Buy it now

img

Toshiba Satellite C850D-11Q (PSCC2E-00R00JEN)

£279.97- Buy it now

img

ASUS Eee PC X101CH-BLK043S

£239.99- Buy it now

Updating your subscription status Loading

Most popular articles

No matching document

Poll

Do you have Windows 8?

Jargon Buster

Computing terms explained in plain English

Restore Point

A Windows backup of system files and settings.

Great shopping deals from Computeractive

Information currently unavailable