Contact
QR code for the current URL

Story Box-ID: 428289

Imperva Inc. 3400 Bridge Parkway, Suite 101 94065 Redwood Shores, CA, United States http://www.imperva.com
Contact Ms Claire Hojem +44 20 7183 2841
Company logo of Imperva Inc.
Imperva Inc.

Boy-in-the-browser gets aggressive by evading anti-malware

(PresseBox) (London (UK), )
Imperva, the leader in data security, warns Boy-in-the-Browser (BITB) attacks are gaining force as they continue to evade traditional anti-malware software.

Tomer Bitton, from the Imperva Application Defense Center, explains, "Many are familiar with Man-in-the-Browser (MitB) attacks, but most are unaware of the lesser known Boy-in-the-Browser (BitB). Not as sophisticated as MitB, BitB malware has evolved from traditional key loggers and browser session records. The recent spate of BitB trojans that targeted Chilean banks, and their customers, demonstrates that this type of attack is gaining force and continues to evade traditional anti-malware software."

Talking you through the steps of an attack, Tomer outlines how it shapes up, "It all starts with a simple, innocent-looking phishing email that encourages the user to click a link to visit a website for more details. However, rather than then asking the user to divulge personal details - which most are now wise to, it instead tells the user that they need to download the latest version of Adobe Flash Player to view the page. Most users will be duped into believing this and will click the link.

"However, rather than receiving the latest version of Flash, they're actually downloading malware.

"Once "installed" the flash-player Trojan writes itself to the registry, then asks the user to "Run" the programme, which allows it to survive the reboot and infects the machine. To avoid detection, the Trojan creates the new hosts file as read-only file."

Explaining the consequences of having infected the machine with the malware, Tomer continues, "From this point, the malware overwrites the users file mapping of hostnames (URL) to network address (IP) mechanism. The next time the user tries to connect to a banking application, or other frequently visited URL, the Trojan instead redirects the user to a fake site controlled by the criminals, which mimics the real site. Often it is so cleverly done that the user would struggle to tell the difference. However it is here that the credentials are stolen, or the user is duped into completing a bogus transaction."

Imperva have created a Video to help illustrate how these attacks occur: http://www.youtube.com/...
The publisher indicated in each case (see company info by clicking on image/title or company info in the right-hand column) is solely responsible for the stories above, the event or job offer shown and for the image and audio material displayed. As a rule, the publisher is also the author of the texts and the attached image, audio and information material. The use of information published here is generally free of charge for personal information and editorial processing. Please clarify any copyright issues with the stated publisher before further use. In case of publication, please send a specimen copy to service@pressebox.de.
Important note:

Systematic data storage as well as the use of even parts of this database are only permitted with the written consent of unn | UNITED NEWS NETWORK GmbH.

unn | UNITED NEWS NETWORK GmbH 2002–2024, All rights reserved

The publisher indicated in each case (see company info by clicking on image/title or company info in the right-hand column) is solely responsible for the stories above, the event or job offer shown and for the image and audio material displayed. As a rule, the publisher is also the author of the texts and the attached image, audio and information material. The use of information published here is generally free of charge for personal information and editorial processing. Please clarify any copyright issues with the stated publisher before further use. In case of publication, please send a specimen copy to service@pressebox.de.