Dangerous Banking Trojan “Vawtrak” Harvests Passwords Using Favicons
New features have been found concerning the dangerous banking Vawtrak malware that allow the malware to send and receive data through encrypted favicons distributed through the Tor network. This malware is used to harvest banking, gaming, and social media details, such as passwords, and is considered one of the worst single threats in existence. It uses Tor2Web proxy to receive updates from its cyber criminal developers and can access and update servers that are hosted on the Tor hidden web services without having to use specialist software such as Torbrowser. The communication with the remote server is done over SSL, which adds deeper encryption.
