Fortinet Blog | News and Threat Research

  • Products
  • Solutions
  • Service & Support
  • Partners
  • Corporate
  • Resources
  • How to Buy

Eurograbber is Zitmo

by RSS Axelle Apvrille  |  December 07, 2012  |  Category: Security Research

Zitmo Attack Scenario - taken from my slides at ShmooCon, January 2011

Zitmo’s attack scenario, taken from CheckPoint’s and VerSafe’s white paper (Dec 2012)

Recently, Check Point and Versafe published a white paper on a mobile banking trojan they named Eurograbber. In fact, this is not new, it is called Zitmo, and s21sec, and Fortinet (and others !) have been talking about it for nearly two years.

In January 2011, Kyle Yang and I presented full details of Zitmo at ShmooCon: the attack scenario, the syntax of commands, the processing of incoming SMS, the relationship with SMS Monitor. We even showed hidden debug windows left by the attackers and explained how to spoof the attacker.  Why isn’t our work and our peers even mentioned? Scientific papers provide references and state of the art sections, and this only seems fair to me. So much for the ethics side.

On the technical side, a few issues should also be noted:

* CheckPoint and VerSafe obviously had access to some C&C - which is interesting. Unfortunately, they don’t explain how. We assume the figures of 36 million stolen euros and 30,000 victims come from there. However, it should be noted that some researchers said the screenshots in the whitepaper were actually account balances and not stolen money. Let’s wait and see who’s right on that point, and let’s just keep in mind the figures might be wrong.

* Contrary to what is said in the report, Zitmo’s attack scenario does not require the victim to log into his/her bank account. Perhaps it occurred that way, but it is not required. At ShmooCon, we explained that, once infected, the whole process could occur while the victim was sleeping…

* Curiously,** all so-called “Eurograbber” samples we analyzed were already detected, except two new Symbian samples, which we are now detecting as SymbOS/Zitmo.C!tr.spy.** That variant is a simplified version of  version A or B, and it has the particularity of using Qt for Symbian, and sending by SMS the GPS coordinates of a street in France, close to Orléans(no clue why so far). We hadn’t seen new versions on Symbian for a while, this is interesting.

Finally, the most interesting point is certainly that this study is the proof Zitmo is being used actively in the wild. So go check your bank accounts now ;)

– the Crypto Girl

Zitmo References

* D. Barroso, ZeuS Mitmo: Man-in-the-mobile, September 25, 2010.

* A. Apvrille, ZeuS in the Mobile (Zitmo): online banking’s two factor authentication defeated, September 27, 2010

* A. Apvrille, Zitmo follow up: from spyware to malware, September 28, 2010

* A. Apvrille, K. Yang, Defeating mTANs for profit, ShmooCon 2011, Washington DC, USA, January 28-30 2011

* Piotr Konieczny, ZeuS straszy polskie banki (ING i mBank), February 21, 2011

* S. Sullivan, Zeus Mitmo Strikes Again: Polish ING Bank, February 21, 2011

* A. Apvrille, What’s New in Zitmo.B, February 23, 2011

* D. Masslenikov, ZeuS in the Mobile: Facts and Theories, October 6, 2011

* A. Apvrille, K. Yang, Defeating mTANs for Profit - part one and part two, Virus Bulletin, March-April 2011

* A. Apvrille, Zitmo hits Android, July 8, 2011

* M. Boodaei, Mobile Malware: Why Fraudsters Are Two Steps Ahead, July 11, 2011

* D. Masslenikov, Zeus-in-the-Mobile for Android, July 12, 2011

* C. Castillo, Spitmo vs Zitmo: Banking Trojans Target Android, September 14, 2011

* D. Desai, Malware Analysis Report Trojan: AndroidOS/Zitmo, September 2011

* D. Masslenikov, Android Security Suite Premium = New ZitMo, June 18, 2012

* A. Apvrille, Controlling Android/Zitmo by SMS commands, June 21, 2012

* D. Masslenikov, New ZitMo for Android and BlackBerry, August 7, 2012

* T. Strazzere, Android Zitmo Analysis: Now you see me, now you don’t, August 13, 2012

* K. de Pontevès, Zitmo timeline, November 19, 2012

* … I am stopping here. I hope I made the point Zitmo is not new ;)

by RSS Axelle Apvrille  |  December 07, 2012  |  Category: Security Research
Tags: android eurograbber Malware mitmo symbian trojan Zeus zitmo
comments powered by Disqus

Category

  • All
  • RSS Subscribe
  • Security Research
  • RSS Subscribe
  • Industry Trends & News
  • RSS Subscribe

FortiGuard Labs on the Web

  • Twitter Twitter
  • Facebook Facebook
  • LinkedIn LinkedIn
  • Youtube Youtube

Monthly Archives

  • May 2013 7
  • April 2013 17
  • March 2013 12
  • February 2013 11
  • January 2013 12
  • December 2012 8
  • November 2012 7
  • October 2012 4
  • September 2012 7
  • August 2012 7
  • July 2012 9
  • June 2012 17
  • May 2012 14
  • April 2012 16
  • March 2012 15
  • February 2012 11
  • January 2012 6
  • December 2011 4
  • November 2011 6
  • October 2011 11
  • September 2011 2
  • August 2011 2
  • July 2011 4
  • June 2011 6
  • May 2011 6
  • April 2011 5
  • March 2011 7
  • February 2011 5
  • January 2011 7
  • December 2010 8
  • November 2010 11
  • October 2010 3
  • September 2010 8
  • August 2010 4
  • July 2010 9
  • June 2010 9
  • May 2010 9
  • April 2010 6
  • March 2010 8
  • February 2010 6
  • January 2010 9
  • December 2009 8
  • November 2009 6
  • October 2009 6
  • September 2009 8
  • August 2009 5
  • July 2009 8
  • June 2009 7
  • May 2009 4
  • April 2009 7
  • March 2009 9
  • February 2009 4
  • January 2009 1
  • Older

Popular topics

Security exploit Malware mobile Cryptography challenge Firewall trojan virut facebook Research Fortinet android mobile phones Zeus symbos/yxes microsoft hacking challenge webinar botnet Threat Landscape symbian Anonymous UTM reversing network security adobe apple conference symbianos iphone hashdays mobile phone stuxnet Antivirus mobile malware zitmo derek manky sms google bredolab Mac OS X Windows BYOD FortiGate reverse engineering Mobile Security Anti-Spam SpyEye privacy