Son of Zeus can sneak past antivirus controls
The latest Trojan horse proves difficult to rein in.
Trend Micro has reported a new variant of the Zeus Trojan will not be detected by conventional antivirus applications. In fact, it has proved to be virtually undetectable.
Zeus has proved to be a persistent threat and was responsible for the recent 6 million theft from UK bank accounts by an international gang. This latest evolution of the Trojan means more financial misery could be happening, with computer users unaware their PC had been involved.
The latest variant has been given the typically ungainly name TSPY_ZBOT.BYZ. It has avoided detection by importing a large number of application programming interfaces (APIs), making it difficult to know where it would strike.
The new Zeus is also compressed differently to its predecessors, which foils a detection system based on calculable entropy. This is finding where in the viral code certain trigger routines might be hidden. It has enabled the Trojan to fool the heuristic detection systems in antivirus protection systems.
In addition to these features, analysing the virus has proved difficult for the numerous labs that develop counter measures. Normally, a virus is isolated in a sandbox, or isolated environment, to see how the code executed, what system changes it made and any network traffic it generated. Zeus just refused to play in a sandbox, Trend Micro claimed.
Since the appearance of Zeus.BYZ, another variant, Zeus.SMEQ, has been found and, given the difficulty in detection, there may have been more added to the family.
Trend's experts, and all the other antivirus companies, have been working on a detection process.
Get the ITPro. daily newsletter
Receive our latest news, industry updates, featured resources and more. Sign up today to receive our FREE report on AI cyber crime & security - newly updated for 2024.
Julius Dizon, research engineer at Trend Micro, concluded: "To properly guard against this threat, conventional antivirus is not sufficient. Both improved detection techniques and proactive blocking of the websites, working together, can protect users."
Jennifer Scott is a former freelance journalist and currently political reporter for Sky News. She has a varied writing history, having started her career at Dennis Publishing, working in various roles across its business technology titles, including ITPro. Jennifer has specialised in a number of areas over the years and has produced a wealth of content for ITPro, focusing largely on data storage, networking, cloud computing, and telecommunications.
Most recently Jennifer has turned her skills to the political sphere and broadcast journalism, where she has worked for the BBC as a political reporter, before moving to Sky News.