390 likes | 560 Views
ZeuS MitMo. Mikel Gastesi 2011-02-25 S21sec e- crime analyst. ZeuS MitMo. Introduction Banking protections Banking trojans ZeuS / Zbot ZeuS MitMo Conclusion. Introduction. Introduction. Target Why the user ??. Banking protections. User / password
E N D
ZeuSMitMo Mikel Gastesi 2011-02-25 S21sec e-crimeanalyst http://nullcon.net/
ZeuSMitMo http://nullcon.net/ • Introduction • Banking protections • Banking trojans • ZeuS / Zbot • ZeuSMitMo • Conclusion
Introduction http://nullcon.net/
Introduction http://nullcon.net/ • Target • Whytheuser??
Bankingprotections http://nullcon.net/ • User / password • User / password + extra passwordfortransactions • Codecard • OTP • mTAN = mobileTransactionauthenticationnumber
Cat and mouse game http://nullcon.net/ • User / password Formgrabbing • User / password + extra passwordfortransactions Formgrabbing • Codecard HTML Injection • OTP • mTAN = mobileTransactionauthenticationnumber Zitmo, MITB • Token?
Attackingtheuser http://nullcon.net/ • Phishing • Trojans • Oneshottrojans • Modifying host file • Formgrabbing • HTML injection
Bankingtrojans http://nullcon.net/ ZeuS / Zbot SpyEye Bankpatch SilentBanker Sinowal Gozi Carberp …
Zbot http://nullcon.net/ • You can buyitforlessthan 600$ ! • Easytoinstall • Easyto configure • Createsaneasy-to-managebotnet • Verypowerful • Add-ons • IM / Jabber • Zitmo has beenseenfor sale!! ¿?¿?
Zbot http://nullcon.net/ Characteristics: • Creates a botnet • Configurationfileupdate • Binaryfileupdate • /etc/hosts modification • Socks proxy • HTML injection • HTML redirection
Zbot http://nullcon.net/ Characteristics: • Screenshots • Captures virtual keyboards • Captures form data • Stealscertificates • KillOSfunction! • Encryptsconfigurationfile and data
Zbot http://nullcon.net/
Zbot http://nullcon.net/
Zbot http://nullcon.net/ • Whydoesitwork so good? • Stealth • Userdoesn’tseeanythingwrong Green lock + https = OK?? #FAIL
Zbot http://nullcon.net/
Zbot http://nullcon.net/
Zbot http://nullcon.net/
Zbot http://nullcon.net/ Screen capture
Zbot http://nullcon.net/ Redirection
Zbot http://nullcon.net/
Jumping tothephone http://nullcon.net/
Attackingphones http://nullcon.net/ • Today - Why? • Stealing OTP • Hiddinginformationmessages (instead of SMS flooding) • Avoiddetection of MitB • Blockingincomingcalls • Prevent s communicatingwithbank • No mail • No SMS • No phonecall
Attackingphones http://nullcon.net/ • Today and Tomorrow – Why? • False Security perception • 2 factors 1 factor • Personal information • Passwords of a lot of services, social networks, etc. • Passwordreuse?
Implementation http://nullcon.net/ • OTP != mTAN • Hardware token • Ownableplatform • How do you configure yourphonenumber?
Zitmo CREDENTIALS 0023424 • 0023424 : OTP COMMANDS http://nullcon.net/
Zitmo http://nullcon.net/ Zeus 2.0.8.9 withcustominjection
Zitmo http://nullcon.net/ Fake SMS toinstallthetrojan (one-time URL)
Zitmo http://nullcon.net/ • Platforms • Symbian • BlackBerry • Windows Mobile • Targets • SpanishbanksonSeptember (+1 german) • Polishbanksthisweek (+ portugal…) • ZitMo dependes only in the PC ZeuSconfig
Zitmo http://nullcon.net/ • Howdoesitwork? • Preconfiguredadminphonenumber • Hellomessage: “Appinstalled OK” • Resendmessages • Inspiredon “SMS Monitor”
Zitmo http://nullcon.net/ • Commands: • Set admin • Senderadd • Sender rem • Block on • Block off • Set sender
Zitmo http://nullcon.net/ Mikel, don’tforgetthe video!!!
ZitMoreloaded http://nullcon.net/ ZeuSversion 3.1.8 Fake?
ZitMoreloaded http://nullcon.net/ New UNINSTALL 45930 command
ZitMoreloaded http://nullcon.net/ Set admin Appinstalled ok
ZitMoreloaded http://nullcon.net/ Androidversion??? FAKE?
Conclusions http://nullcon.net/ • Real threat, activelyused • Defeats OTP (mTAN) • Tothink: 2 factor authenticationisbecoming single authentication! • Android > Symbian • Samescenario? • Installingfromthe web androidmarket?
Questions? http://nullcon.net/
http://nullcon.net/ Thankyou!!! Contact: mgastesi@s21sec.com