Home Malware Programs Trojans TSPY_ZBOT.THY

TSPY_ZBOT.THY

Posted: August 21, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 94
First Seen: August 21, 2013
OS(es) Affected: Windows

TSPY_ZBOT.THY is a Trojan that is a variant of KINS banking Trojan (dubbed 'the next ZeuS' by media reports). TSPY_ZBOT.THY carries sophisticated anti-debugging and anti-analysis routines. To prevent analysis and debugging, TSPY_ZBOT.THY searches for and stops running if it finds it is being run inside several popular virtual machine servers (specifically, VMWare and VirtualBox) or a Windows emulator (WINE). Similarly, other security applications like Sandboxie will also cause TSPY_ZBOT.THY to stop running. TSPY_ZBOT.THY downloads a configuration file that includes the list of targeted banks, drops zone websites, and webinjects files. TSPY_ZBOT.THY steals online banking data such as user credentials by inserting a specific code onto the attacked PC user's Internet browsers when he/she visits specific web addresses in real time. When done, TSPY_ZBOT.THY shows fake legal pop-up alerts that ask for banking credentials and additional information such as social security number.

Loading...