Stabuniq trojan found on servers at U.S. banks

Share this article:

An information-gathering trojan has successfully compromised servers at a number of U.S. financial institutions, according to researchers at security firm Symantec.

Researchers said that of roughly 40 IP addresses infected with the trojan, known as Stabuniq, 39 percent belong to financial institutions, mostly in Chicago and New York. The trojan apparently spreads through targeted emails or via compromised websites that serve malware through exploit kits.

"These financial institutions had their outer perimeter breached, as the trojan has been found on mail servers, firewalls, proxy servers and gateways," Symantec software engineer Fred Gutierrez wrote Thursday in a blog post

Compromises are limited because Stabuniq's creators seem to be "targeting specific people and entities," he said. The current goal of the operation appears to be reconnaissance, not fraud.

The security firm also found successful hijacks at security solutions providers – likely because they were studying the threat – and on the computers of home users.

Share this article:
You must be a registered member of SC Magazine to post a comment.

Sign up to our newsletters

TOP COMMENTS

More in News

Information sharing requires breaking down barriers, White House cyber guru says

Information sharing requires breaking down barriers, White House ...

The White House has advanced an agenda to promote and facilitate information sharing on security threats and vulnerabilities.

Worm variant of Android ransomware, Koler, spreads via SMS

Worm variant of Android ransomware, Koler, spreads via ...

Upon infection, the Koler variant will send an SMS message to all contacts in the device's address book.

Patch for Windows flaw can be bypassed, prompts temporary fix from Microsoft

Patch for Windows flaw can be bypassed, prompts ...

The Windows zero-day received a patch last week, but the fix can still be bypassed by crafty attackers.