Threat Management, Malware

Targeting U.S. banks, Qbot trojan evolves with new evasion techniques

By malware standards, the banking trojan Qbot is long in the tooth, but it still has some bite, according to researchers who say it has added some detection and research evasion techniques to its arsenal.

"It has a new packing layer that scrambles and hides the code from scanners and signature-based tools," wrote Doron Voolf, malware analyst at F5 Labs (part of F5 Networks), in a recent company blog post. "It also includes anti-virtual machine techniques, which helps it resist forensic examination."

F5 Labs discovered the new additions while analyzing a Qbot sample that was detected earlier this year. Active since 2008, Qbot is designed to collect victims' browsing activity and steal their bank account credentials via keylogging, credential theft, cookie exfiltration, and process hooking, Voolf notes.

This latest sample was programmed to harvest credentials primarily from U.S. banks and their online financial services offerings. F5 identified 36 targeted U.S. financial institutions and two banks in Canada and the Netherlands, including J.P. Morgan, Citibank, Fifth Third Bank, U.S. Bancorp, Citizens Bank, Keybank, Bank of America, Capital One, First Citizens Bancshares, First Horizon Bank, SunTrust, Compass Bank, TD Bank, Wells Fargo, Frost Bank, TCF Bank, Huntington Bancshares, M&T Bank, Scotiabank, First Merit Corporation, Eastern Bank, ABN AMRO, PNC Bank, Silicon Valley Bank and others. The researchers also found six generic URL targets "that might be added as a second stage in the fraud action."

Bradley Barth

As director of multimedia content strategy at CyberRisk Alliance, Bradley Barth develops content for online conferences, webcasts, podcasts video/multimedia projects — often serving as moderator or host. For nearly six years, he wrote and reported for SC Media as deputy editor and, before that, senior reporter. He was previously a program executive with the tech-focused PR firm Voxus. Past journalistic experience includes stints as business editor at Executive Technology, a staff writer at New York Sportscene and a freelance journalist covering travel and entertainment. In his spare time, Bradley also writes screenplays.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds