Potential trojan redirects users to malicious websites

Share this article:

Users of online banking and credit card websites were warned this week of a potential trojan that redirects users to fake financial sites - even if users type in the correct URL themselves.

Calling the potential trojan DNSChanger.eg, researchers at MicroWorld Technologies said Monday that the malware can redirect users to sites that closely resemble authentic financial websites.

The trojan operates by corrupting the process of translating a domain name to the actual website, according to a statement released by MicroWorld on Monday.

After a user types in the web address of a financial institution, which is then translated into a string of numerical information, the trojan changes the NameServer Registry key to a fraudulent IP address, according to MicroWorld.

Govind Rammurthy, MicroWorld CEO, said in a statement that the trojan is "threatening the very fundamentals on which the world does business online."

"If phishing requires you to be lured through emails that lead you to imposter websites, this one needs none of that sort. While the unsuspecting user continues an online transaction in good faith, he could be playing directly into the hands of a remote fraudster," he said. "It’s like creating a make-believe world to fine perfection and then looting everything that a victim has."

Share this article:

Sign up to our newsletters

More in News

In Cisco probe, misuse or compromise spotted on all firms' networks

In Cisco probe, misuse or compromise spotted on ...

Cisco analyzed the business networks of 30 multinational companies last year, and revealed the findings in its 2014 Annual Security Report.

Fareit trojan observed spreading Necurs, Zbot and CryptoLocker

The Necurs and Zbot trojans, as well as CryptoLocker ransomware, has been observed by researchers as being spread through another trojan, known as Fareit.

Post Heartbleed, tech giants join initiative to bolster open source

Post Heartbleed, tech giants join initiative to bolster ...

The newly formed Core Infrastructure Initiative, created to boost under-funded open source projects, will tackle OpenSSL first.