
Specialists of the Center for Viral Research and Analysts by ESET revealed a new version of the Butokta ROVNIX, previously present as part of the Trojan Carberp program, which allows attackers to attack the remote banking service (DBO) and devastate the accounts of both legal entities and individuals.
According to ITAR-TASS with reference to the press service of the antivirus software developer, Rovnix is an expandable tool for building Butitkin with any payload for the implementation of subsequent attacks.
Betkitami, recall, are called malicious programs that modify the MBR boot sector (Master Boot Record), the first physical sector on the computer’s hard disk. The main functionality of the Butotkita is the creation of a botnet - a network of infected computers, using which you can make DDOS attacks, send spam, as well as upload any malware to the user system.
As part of the Trojan Carberp program, the ROVNIX Butkit has existed from the autumn of last year to the spring of the current one, after which the attackers switched to the installation scheme of the Buttk-components in a special team from the Center for General PRO management.
In the new modification of ROVNIX, protection against antivirus software is improved and functionality has been expanded. In particular, now Rovnix can perform several harmful tasks in the system at once, for example, simultaneously perform DDOS attacks and steal confidential data. ROVNIX, thus, is the first Butykit to use the methodology of detour from antivirus products.
According to ESET experts, Rovnix was actively sold at the beginning of last year, and its cost was 60 thousand dollars. The purchase also provided for several months of support from the developers.
In the second half of last year, Russia became the absolute leader in the number of incidents in the field of information security using Carberp Trojan, which affects the DBO system. The latest versions of this malicious software are able to steal financial resources even from those computers of the corporate network where they do not have administrator rights.
According to experts, the average damage of one legal entity, which is a client of the Russian bank from a successful hacker attack is 300-400 thousand rubles. From the accounts of individuals, the average attempt to fraudulent write -off reaches 50 thousand rubles. On average, about 50 attacks occur per day.
Almost every Russian bank is subjected to attacks from time to time, and only from next year, after the entry into force of the Law "On the National Payment System" (NPS), banks will have to reimburse losses from transactions unauthorized by clients.