Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Banking Malware Targets Wire Transfers; Evades Antivirus
Articles

Banking Malware Targets Wire Transfers; Evades Antivirus

ISB Editorial StaffBy ISB Editorial StaffApril 8, 2015Updated:July 4, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
banking malware Dyre
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The Trojan Dyre (also known as Dyreza) has been around for quite awhile now, terrorizing the banking industry, stealing passwords and enabling malicious hackers to make off with money stolen directly from individual accounts.

Now IBM security researchers are reporting on a recent campaign they’ve dubbed, “The Dyre Wolf” that leverages social engineering to steal account inf ormation and money from corporate accounts – resulting in higher payoffs. IBM reports that attackers have stolen upwards of a million dollars using this campaign.

IBM researchers have found that attackers are targeting companies that often conduct high-dollar wire transfers. They also noted that most antivirus tools were unable to detect this Dyre malware variant, suggesting that traditional security solutions aren’t enough to stop password-stealing malware.

Social Engineering to Steal Wire Transfers

The attackers have crafted an elaborate scheme involving a call center to intercept wire transfers. Once infected, users are presented with a fake prompt when they attempt to visit a banking website. The prompt tells the user that the site is experiencing issues, and urges him/her to call a phone number for customer service assistance – effectively stealing both their login and the wire transfer money.

Attackers may target some companies with a DDoS (Distributed Denial-of-Service) attack in order to distract them from finding the wire transfer until it was successfully delivered to their own bank account, a commonly used and effective diversion tactic.

In addition, if the Dyre malware detects that Microsoft Outlook is installed on the user’s computer, it attempts to spread itself via emails and attachments to contacts listed in their email account, according to the IBM report, The Dyre Wolf: Attacks on Corporate Banking Accounts (PDF).

The spread of this malware isn’t slowing down. According to research in October 2014, IBM found that instances of Dyre infection had risen from 500 to nearly 3,500 – an increase of 600 percent.

Moar Banking Malware & Drive-By Downloads

And obviously, Dyre isn’t the only banking trojan out there. Another recent malware campaign targeting more than 15 Canadian financial institutions involves the Neverquest banking trojan, according to SCMagazine.com. Vawtrak, the latest variant of Neverquest, leverages man-in-the-middle attacks, videos and screenshots to steal online banking credentials and log into accounts via remote connections to their PCs to evade detection.

The malware is spread to victims via drive-by download. Drive-by downloads also targeted jQuery.com visitors last September, when a malicious script was added to the website by attackers in an invisible iframe. Visitors were redirected to an exploit kit that installed credential-stealing malware on their machines. Learn more in jQuery Credential-Stealing Attack Targets Sys Admins and Web Developers.

Last October, Spin.com and Popular Science magazine were also hit by drive-by download malware that similarly redirected to an exploit kit that installed data-stealing malware on vistors’ computers. The exploit kit searched for known vulnerabilities in different applications, including those affecting Microsoft IE, Silverlight, Oracle Java SE and Adobe Flash Player.

Find out more about how website owners can check for malicious code and deter infection in University, Online Magazines & JavaScript Sites Hit By Drive-By Malware.

How can you protect your organization from banking malware? IBM’s recommendations include:

  • Reboot after any type of detection
  • Restrict execution of programs from temp folders
  • Maximize network visibility
  • End-user education

To learn about this banking malware, please read the rest of this article on Duo Security’s blog here.

By Thu Pham, Information Security Journalist, Duo Security | @Thu_Duo

Thu Pham covers current events in the tech industry with a focus on information security. Prior to joining Duo, Thu covered security and compliance for the infrastructure as a service (IaaS) industry at Online Tech. Based in Ann Arbor, Michigan, she earned her BS in Journalism from Central Michigan University.

 

About Duo Security

Duo Security is on a mission to provide advanced security solutions for organizations of all sizes. Duo’s innovative technology protects users, data and applications from credential theft and breaches with a focus on streamlined usability. The company was co-founded by CEO Dug Song, a major contributor to the security community, and CTO Jon Oberheide, expert cloud, mobile, and malware security researcher.

ISB Editorial Staff
  • ISB Editorial Staff
    Navigating the Cyber Threat Landscape: Key Insights from Trellix ARC’s Q1 2023 Report
  • ISB Editorial Staff
    Experts’ Responses: Cyber Security Predictions 2022
  • ISB Editorial Staff
    ISB Virtual Conference: Key Cyber Security Challenges and Solutions in 2021
  • ISB Editorial Staff
    Cyber Security Predictions 2021: Experts’ Responses

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}