Functions from both malware families used by this hybrid beast to target 450 financial firms Researchers at Trusteer have discovered a new Trojan circulating online, which uses functions from both the Zeus and the Carberp families of malware.In 2011, the source code for the Zeus Trojan was leaked to the public, and criminals have been using parts of it ever since. Last year, the Carberp source code was offered for sale online, and researchers speculated that it could be added to Zeus or other malware families due to its versatility.“Since the source code of the Carberp Trojan was leaked to the public, we had a theory that it won’t take cyber criminals too long to combine the Carberp source code with the Zeus code and create an evil monster,” explained Trusteer’s Martin G. Korman and Tal Darsan, in a statement.“It was only a theory, but a few weeks ago we found samples of the ‘Andromeda’ botnet that were downloading the hybrid beast.” This “hybrid beast” as it’s being called, is a variant of ZeusVM, which itself is a variant of Zeus discovered earlier this year. ZeusVM is a notable advancement to Zeus, as the malware’s authors use steganography as a means of hiding configuration data within images.The connection between ZeusVM and the hybrid Zeus / Carberp Trojan, called Zberp by Trusteer, is the same use of steganography to hide configurations. The technique is useful for avoiding detection, and the attacks observed by Trusteer have used an Apple logo to transmit updates between infected hosts. Zberp combines a range of features that originated from the Zeus and Carberp families, including information gathering (IP address and host name); capturing screenshots and uploading them to a remote server; FTP and POP3 credential harvesting; harvesting information entered into Web forms; the ability to hijack browsing sessions and insert rogue content; and initiate remote desktop connections via VNC or RDP.In addition to the shared functionality, Zberp also uses some of the same evasion techniques that are found in both Zeus and Carberp. This includes the “invisible persistence” feature that’s found within ZeusVM.“…the malware deletes its persistence key from the registry during the Windows startup process to prevent security solutions from detecting it during normal system scans that take place after the system boots. To ensure persistency, however, the malware rewrites the persistence key back to the registry during system shutdown,” Trusteer’s researchers said, explaining the invisible persistence function.As with the previous versions of Zeus and Carberp, this hybrid creation targets more than 450 financial firms in the U.S., U.K. and Australia – though Trusteer didn’t identify those firms directly.In the past, criminals have focused on financial targets that are relevant to the regions where the victim’s lived, increasing their odds of success. Additional information is available from Trusteer. Related content news Gwinnett Medical Center investigating possible data breach After being contacted by Salted Hash, Gwinnett Medical Center has confirmed they're investigating a security incident By Steve Ragan Oct 02, 2018 6 mins Regulation Data Breach Hacking news Facebook: 30 million accounts impacted by security flaw (updated) In a blog post, Facebook’s VP of product management Guy Rosen said the attackers exploited a flaw in the website's 'View As' function By Steve Ragan Sep 28, 2018 4 mins Data Breach Security news Scammers pose as CNN's Wolf Blitzer, target security professionals Did they really think this would work? By Steve Ragan Sep 04, 2018 2 mins Phishing Social Engineering Security news Congress pushes MITRE to fix CVE program, suggests regular reviews and stable funding After a year of investigation into the Common Vulnerabilities and Exposures (CVE) program, the Energy and Commerce Committee has some suggestions as to how it can be improved By Steve Ragan Aug 27, 2018 3 mins Vulnerabilities Security Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe