Rechercher
Contactez-nous Suivez-nous sur Twitter En francais English Language
 

Freely subscribe to our NEWSLETTER

Newsletter FR

Newsletter EN

Vulnérabilités

Unsubscribe

Amit Klein, CTO, Trusteer : how Zeus is stealing logon credentials to enterprise access gateways giving an example of Citrix

November 2010 by Amit Klein, CTO, Trusteer

We’re all familiar with Zeus, the king of financial malware. It is infamous for targeting banks, credit unions and financial institutions. Zeus silently steals password and account information from customers of these institutions, and uses their credentials to execute fraudulent money transfers.

Once Zeus is installed on a victim’s machine, it fetches a configuration file from one of its command and control servers. The configuration file instructs Zeus which websites and applications to target, which information to steal, and how to steal it. This information is encrypted and is usually hard to capture. As part of our ongoing research we capture and decrypt Zeus configurations to study them. Some of the Zeus 2.0 configurations we recently decrypted include the following code:

In English, this string tells Zeus the following:

The "@" means "capture a screenshot of the text within the mouse’s vicinity when the left button is clicked"

The */citrix/* further specifies that this screenshot should be captured when the text "/citrix/" appears in the browser address bar.

This code instructs Zeus to take a screen shot every time the left button is clicked while the browser’s URL includes the term "/citrix/".

What Zeus is doing here is trying to capture login credentials from users of the Citrix Access Gateway (http://www.citrix.com/English/ps2/products/feature.asp?contentID=2300359), a popular SSL VPN solution used by businesses to provide secure remote access to applications and data inside their protected network. Criminals always seek the path of least resistance. In the case of enterprise networks the least secure path is through mobile and remote employee computers, which are outside the control of most internal IT departments.

Citrix is well aware and concerned about the threat of keyloggers and their ability to capture a user’s login information for the Citrix Access Gateway. In order to protect against this type of attack, Citrix developed a virtual keyboard solution. According to the Citrix website: "Keyloggers are becoming an increasing threat on the internet, and pose a risk to security of corporate networks. They are applications that run silently on a PC or internet kiosk and record the keystrokes entered by a user for later review. They pose a risk because they can capture usernames and passwords entered, which can then be reviewed and used in obtaining unauthorized access to the corporate network.”

The Citrix Access Gateway allows companies to customize the logon page to include a virtual on-screen keyboard which replaces the physical keyboard. So instead of typing a password on the physical keyboard, mouse clicks are used to press the keys drawn on screen. This approach prevents keyloggers from capturing keystrokes, since there are none to capture.

The Zeus configuration snippet shown above is specifically designed to defeat the virtual keyboard capability in the Citrix Access Gateway. By capturing screenshots within the vicinity of the pointer during mouse clicks, Zeus is able to read the user’s password which will clearly show up as the sequence of keys the mouse pointer was pointing at when the mouse was clicked.

This attack code clearly illustrates that Zeus is actively targeting enterprises and specifically remote access connections into secure networks. Fraudsters are no longer satisfied with simply going after bank accounts. They are also targeting intellectual property and sensitive information contained in company IT networks and applications. Users of remote access VPN systems like the Citrix Access Gateway (employees, contractors, and partners) are purposely being targeted because their computers are unmanaged and can easily be compromised with sophisticated malware like Zeus. As a result, corporate

IT departments should be aware of this threat and take steps to protect their unmanaged computers and remote sessions. These include limiting VPN access to specific applications and users, maintaining up to date malware protection on remote devices, using a secure browsing service to protect VPN connections, and educating users on computer hygiene and secure browsing best practices.


See previous articles

    

See next articles


Your podcast Here

New, you can have your Podcast here. Contact us for more information ask:
Marc Brami
Phone: +33 1 40 92 05 55
Mail: ipsimp@free.fr

All new podcasts