Follow Us

War on Error

The Zeus bank Trojan is stealing money with impunity. Can it be stopped?



It’s been called the ‘second bank crisis’, and this time the cause is a piece of malware so potent it can steal money from online bank accounts with apparent impunity.

It’s name is Zeus (or Zbot) and it’s mighty clever. Rather like the investment bankers of unpopular lore, it does what it does quietly, behind the wall of bank secrecy, and so almost nobody has heard of it.

If a gang walked through the front door of a bank branch and made off with tens of millions, it would be front page news and yet even today’s widely-reported arrest of 19 people accused of being involved with using Zeus to hack online accounts still feels like a passing curiosity. And this is only the latest in a long line of incidents.

It shouldn’t be. Zeus has been attacking UK, US and European bank account holders for some time now, and its success tells us that something is profoundly wrong.

Beyond the headlines, what can be done to fight Zeus and other similar targeted malware of the near future?

Stop kidding ourselves that antivirus software is reliable enough to use as a sole defence against targeted malware. There is plenty of evidence that Zeus can get round almost all popular AV programs using polymorphic variants.

Promote second-line security software such as the Trusteer Rapport  browser plug-in (Zeus does its work inside browsers), or go even further and embrace virtualised browsers run from media such as USB sticks. There are plenty of options around but we need more choices.

Banks should wake up and start promoting such security as a requirement of using online banks. They could also perform remote scans on user’s PCs, refusing to hook up to people daft enough to stick with high-risk browsers such as IE 6, still used by a surprising number of people.

The final layer of the defence system is good policing of the sort that led to today’s and last month’s Zeus-related arrests. The vulnerability of Zeus is not technical but human. The people wielding from it leave traces of their actions and that is where e-crime needs to attacked more often..

But high-tech coppery will never be enough on its own because they can’t fight a labyrinth of gangs with limited resources. Consequently, banks need to stop hiding this problem behind a wall of secrecy. The industry needs to learn from the problems of other institutions and intelligence needs to be shared in real time. The bank industry needs an incident response team, probably a global one.

Until some or all of the above goes happens, let’s take it as read that today’s Zeus bust will not be the last and its victims will continue to mount.


Tags: online banking, security, zbot, zeus trojan

RSSSubscribe to this blog

Contact Us

For editorial queries:
Mike Simons Mike_Simons@idg.co.uk

For website issues:
Email webmaster@techworld.com

For commercial queries
Russell Kearney russell_kearney@idg.co.uk


For more contact details click here.


Email this to a friend

* indicates mandatory field





Techworld White Papers

Optimising data protection for virtual environments

VM environments require the same level of data protection as does the physical server environment. Companies may use data protection tools built for the physical environment in the virtual world, but this has serious disadvantages.

Download Whitepaper

PCI Compliance: Are UK businesses ready?

Exploring the results of a recent survey, including: ? Levels of understanding of the standard ? Current perceptions of actual compliance status ? Attitudes toward addressing compliance

Download Whitepaper

Mobility Management for Dummies

Your complete guide to managing and securing mobile devices such as laptops and smartphones.

Download Whitepaper

Magic Quadrant for midrange and high-end NAS solutions

It is difficult to find one midrange or high-end NAS product that can cater to all needs. File systems embedded in NAS are often designed to solve one major pain point, with additional features being added later to broaden use cases and benefits.

Download Whitepaper

Techworld UK - Technology - Business

Oracle Video

Enabling agile and intelligent businesses

 Changing markets, competitive pressures and evolving customer needs are placing increasing pressure on IT to deliver greater flexibility and speed. Explore truly flexible SOA foundations with this Oracle video.

Watch
COLT White Paper

IT Misuse Survey

Complete this survey and you could win a Nexus One

Techworld are running a short survey to discover how UK businesses are managing Internet and email misuse in the Enterprise.

Complete Survey

Complete our survey and you could win a Sony E-book Reader.
Techworld have teamed up with HP to compile a survey relating to server virtualisation. Complete the short survey and you could be the lucky winner of a Sony E-book reader.

Complete the survey here

Site Map

Test