Language Selection

English French German Italian Portuguese Spanish

“Hand of Thief” banking trojan doesn’t do Windows—but it does Linux

Filed under
Linux
Security

Signaling criminals' growing interest in attacking non-Windows computers, researchers have discovered banking fraud malware that targets people using the open-source Linux operating system.

Hand of Thief, which was recently discovered by researchers from security firm RSA, sells for about $2,000 in underground Internet forums and boasts its own support and sales agents. Its functionality—consisting of form grabbers and backdoor capabilities—is rudimentary compared to Windows banking trojans spawned from the Citadel or Blackhole exploit kits, but that's likely to change. RSA researcher Limor Kessem said she expects Hand of Thief to become a full-blown banking trojan that includes more advanced features such as the ability to inject attacker-controlled content into trusted bank webpages.

"Although Hand of Thief comes to the underground at a time when commercial trojans are high in demand, writing malware for the Linux OS is uncommon, and for good reason," Kessem wrote. "In comparison to Windows, Linux's user base is smaller, considerably reducing the number of potential victims and thereby the potential fraud gains."

rest here




More in Tux Machines

Security: FOSS Updates, More on Marcus Hutchins

Development: DragonEgg, GCC, LLVM, and Java EE

Kernel and Graphics: Android Kernels, Mesa, and Vulkan 1.0.59

  • Android kernels: does upstream matter?
    There is this false narrative floating around in the dev community on how upstreaming breaks drivers and OEM code. Upstreaming breaking drivers and OEM code is not universally true- in contrast, it defies the very definition of a stable kernel. You see, each and every Android device out there runs a version of the Linux Kernel– and it doesn’t have to be the latest version all the time.
  • Mesa 17.2-RC5 Released, Final Should Come Within One Week
    The fifth and final planned release candidate of Mesa 17.2 is now available for testing.
  • Vulkan 1.0.59 Released With Shader Stencil Export
    Vulkan 1.0.59 is now available this weekend as the latest minor update to this high-performance graphics API. As usual, the bulk of this Vulkan 1.0.x point release is made up of document clarification/fixes to the text. Of those changes, nothing too notable stands out for Vulkan 1.0.59 but there is one new extension.

Games: Pillars of Eternity, Ryan "Icculus" Gordon, Paradox Interactive and HTC Vive