Aug 13, 2012

Gauss: Stuxnet Like Worm Spotted Stealing Banking Information



A new cyber weapon which is believed to be linked with Stuxnet,Duqu,Flame in its operation (i.e to  target Iranian nuclear facility) has been discovered which was aimed at stealing financial information from customers of a series of Lebanese banks.

Like Flame, Gauss is also discovered by ITU (International Telecommunications Union) as part of its mission to maintain world cyber-peace.
Kaspersky said
“Gauss is a nation state sponsored banking Trojan which carries a warhead of unknown designation”. Besides stealing various kinds of data from infected Windows machines, it also includes an unknown, encrypted payload which is activated on certain specific system configurations.
It shares some functionalities with Flame, such as the USB infection subroutines.
Kaspersky made some analsys on this Trojan and released a technical paper  which contains several details about the worm.

Comments system

Disqus Shortname