Home Malware Programs Trojans Trojan.Shylock

Trojan.Shylock

Posted: October 6, 2011

Threat Metric

Threat Level: 8/10
Infected PCs: 11
First Seen: October 6, 2011
OS(es) Affected: Windows

Trojan.Shylock is a banking Trojan that attempts to steal information associated with bank accounts based in the United Kingdom. Like Trojan.Tatanarg – a similar form of spyware – Trojan.Shylock uses man-in-the-middle (also known as MITM, man-in-the-browser or MITB) attacks to compromise normally-secure information transactions to your bank's website. However, what caused SpywareRemove.com malware researchers to raise their eyebrows was Trojan.Shylock's incorporation of a live chat interface in these attacks, which potentially can allow criminals to gather more information via personal interaction. Although Trojan.Shylock's distribution levels are low, the potential damage of Trojan.Shylock's payload can include a compromised bank account, and it's recommended for UK-based PC users to take particular care against possible Trojan.Shylock attacks and infection vectors. Despite its danger, Trojan.Shylock can be deleted by standard anti-malware products without notable difficulties.

When Bank Security Turns Against You with a Little Help from Trojan.Shylock

Although the web page-altering attacks that Trojan.Shylock uses are well-used with other forms of banking Trojans, Trojan.Shylock is unique in how Trojan.Shylock chooses to use these attacks for its own benefit. Once Trojan.Shylock detects that you're attempting to access a United Kingdom bank's website, you'll be treated to a fake message about how 'The system couldn't identify your PC'.' Trojan.Shylock will claim that a representative of the bank will contact you via live chat to confirm your identity. However, this is just an unusually-involved method of allowing Trojan.Shylock's criminals friends to steal additional confidential information about your bank account.

Other JavaScript-based injection attacks by Trojan.Shylock can also alter the contact information for these sites by inserting phone numbers associated with said criminals. Because these phone numbers are disposable and appear to have a rapid turnover rate, it's very likely that attempts to contact them will meet with being forwarded to a different number or no response at all. Like most types of banking Trojans, Trojan.Shylock is designed to avoid any unnecessary symptoms and can even bypass SSL protocol security while making this security measure look like it's still enabled. Accordingly, SpywareRemove.com malware research team recommends using anti-malware programs to detect any potential Trojan.Shylock infection whenever it's necessary.

Guarding Your Fiscal Credentials Against Trojan.Shylock's Thievery

Trojan.Shylock uses rootkit features to conceal itself along with a randomized name and location. Therefore, attempts to isolate and delete Trojan.Shylock should always use anti-malware software unless a PC security professional deems otherwise. Trojan.Shylock may be focused on UK banks, but its distribution has also spread significantly throughout Canada and the United States, and PC users in any of these regions should consider themselves vulnerable to potential Trojan.Shylock attacks.

Trojan.Shylock is a Windows-specific Trojan that affects most versions of the platform, from Windows 95 to Windows 7, although other operating systems are, for the moment, safe from Trojan.Shylock. Even though Trojan.Shylock's current distribution is low, and its removal isn't very challenging for anti-malware programs, the potential damage that Trojan.Shylock can cause to your bank account makes SpywareRemove.com malware analysts rate Trojan.Shylock as a midlevel threat if Trojan.Shylock actually is infecting your computer.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"[GATHERED SYSTEM INFORMATION IN UUID FORMAT]" = "[PATH TO THE TROJAN]"

Related Posts

Loading...