new \gauss\ trojan spies on middle east banks
Last Updated : GMT 06:49:16
Arab Today, arab today
Arab Today, arab today
Last Updated : GMT 06:49:16
Arab Today, arab today

New 'Gauss' Trojan spies on Middle East banks

Arab Today, arab today

Arab Today, arab today New 'Gauss' Trojan spies on Middle East banks

Washington - DW

The newly discovered Gauss Trojan has stolen key data from thousands of bank users in the Middle East. But it's not after money - the malware wants to spy. The Trojan goes by the name Gauss. The Russian IT security firm Kaspersky Lab discovered it in June and has only just now declared it "a new cyber threat targeting users in the Middle East." But the server used to store data collected by Gauss has been shut down. It is thought to have become active in September 2011. It has stolen browser passwords, online banking account credentials, browser histories and cookies from thousands of bank users' computers. Kaspersky Lab says Gauss has targeted the details of customers of several Lebanese banks, including the Bank of Beirut. It has also targeted users of Citibank and the online payment system PayPal. "The online banking Trojan functionality found in Gauss is a unique characteristic that was not found in any previously known cyber-weapons," said Kaspersky Lab in a statement. Stealing data, not money "Gauss targets multiple users in select countries to steal a large amount of data with a specific focus on banking and financial information," says Alexander Gostev, a chief security expert at Kaspersky Lab. Some media have called Gauss "a banking Trojan." But Toralv Dirro, a security strategist at McAfee Labs, says the term is misleading. "It's not a banking Trojan," says Dirro, "the aim of a banking Trojan is to get into the accounts of users to steal money. But Gauss is much more complex than that." Kaspersky Lab says Gauss was designed for espionage. "I think it's plausible," Dirro says. "It's very flexible and consists of several modules, and that's not typical for a banking Trojan." Gauss is similar to another recent Trojan - Flame. The Flame malware was discovered earlier this year and mainly infected machines in Iran. Some say it was designed to spy on the country's nuclear program. The United States and Israel are suspected of being responsible for Flame. Another early malware called Stuxnet tried to attack Iran's nuclear centrifuges. Gauss and Stuxnet also share characteristics. But Gauss seems to have focused exclusively on banks. "A typical banking Trojan would target either very few banks or a long list of them," says Dirro of McAfee Labs. He says Swiss international banks would be on the list if criminals had been behind Gauss. Server shutdown Information seems to be more important than money to the creators of Gauss. By stealing cookies they can see which person was on which website at what time. And by spying on bank accounts they can see exactly how much money moved from one person, or company, to another. But how they will use the data is unclear at present. Gauss is dormant now. And as a Trojan the malware has no way of multiplying and spreading itself like a virus. "The Trojan is still stealing information but it has no master to talk to," says Dirro. The controlling server that Gauss was communicating with was switched off shortly after its discovery - probably by its creators. But users of the German IT specialist website heise.de have been speculating about how the malware could switch to another server and whether it could start sending data again.

arabstoday
arabstoday

Name *

E-mail *

Comment Title*

Comment *

: Characters Left

Mandatory *

Terms of use

Publishing Terms: Not to offend the author, or to persons or sanctities or attacking religions or divine self. And stay away from sectarian and racial incitement and insults.

I agree with the Terms of Use

Security Code*

new \gauss\ trojan spies on middle east banks new \gauss\ trojan spies on middle east banks

 



Name *

E-mail *

Comment Title*

Comment *

: Characters Left

Mandatory *

Terms of use

Publishing Terms: Not to offend the author, or to persons or sanctities or attacking religions or divine self. And stay away from sectarian and racial incitement and insults.

I agree with the Terms of Use

Security Code*

new \gauss\ trojan spies on middle east banks new \gauss\ trojan spies on middle east banks

 



GMT 10:04 2011 Wednesday ,24 August

Exciting summer travel destinations

GMT 20:38 2017 Sunday ,22 October

Bahrain strongly condemns Wahat attack

GMT 03:37 2017 Wednesday ,31 May

De Niro: Once inspiring, US now tragic dumb comedy

GMT 05:22 2017 Tuesday ,13 June

Oil rises as investors buy into US crude

GMT 20:17 2017 Tuesday ,10 October

Iraq recovers bodies of plane crew shot down by IS

GMT 02:26 2017 Thursday ,19 January

Ancient Jewish community endures on Tunisian isle

GMT 10:48 2013 Thursday ,02 May

Mirrors to decorate your home

GMT 13:11 2017 Thursday ,09 March

The goodness of green

GMT 15:21 2017 Sunday ,09 July

UK urged to do more to help solve Gulf rift

GMT 20:39 2017 Thursday ,19 October

Tesla fired hundreds of employees in past week

GMT 18:28 2015 Sunday ,07 June

Wireless credit card machines

GMT 05:49 2017 Friday ,22 September

UN sets up probe of IS atrocities in Iraq

GMT 10:32 2017 Tuesday ,28 March

Amazon expands global reach with Souq.com buy

GMT 10:49 2017 Saturday ,05 August

Russian, Austrian leaders hold talks

GMT 19:32 2017 Tuesday ,31 October

Saudi-Italian cooperation discussed
Arab Today, arab today
 
 Arab Today Facebook,arab today facebook  Arab Today Twitter,arab today twitter Arab Today Rss,arab today rss  Arab Today Youtube,arab today youtube  Arab Today Youtube,arab today youtube

Maintained and developed by Arabs Today Group SAL.
All rights reserved to Arab Today Media Group 2021 ©

Maintained and developed by Arabs Today Group SAL.
All rights reserved to Arab Today Media Group 2021 ©

arabstoday arabstoday arabstoday arabstoday
arabstoday arabstoday arabstoday
arabstoday
بناية النخيل - رأس النبع _ خلف السفارة الفرنسية _بيروت - لبنان
arabstoday, Arabstoday, Arabstoday