Bad Actors behind the Dyre botnet operates like a business

Experts at Symantec observed a significant upsurge in activity over the past year for the Dyre financial Trojan used to target banking customers worldwide

The operators behind the popular Dyre banking trojan appear very active in this period, according to security experts at Symantec they are working hard five-day a week to maintain some 285 command and control servers handling stolen banking credentials.

The Dyre (Dyreza) is a financial malware that is targeting a larger number of banks worldwide, the bad actors behind its botnet handle a large number of domains in order to host botnet handle a large number of domains in order to host phishing websites used to steal banking credentials.

Cyber criminals used more than 1000 websites to clone legitimate site of the US and British organizations in US, Germany, Australia, and France.

The infection vector used to spread the Dyre trojan is the email, bad actors use to send victims messages usually masquerade as business documents, voicemail, or fax messages. The malicious emails come with an attachment or a link to a domain that is used to serve the malicious code.

“A significant upsurge in activity over the past year has seen Dyre emerge as one of the most dangerous financial trojans, capable of defrauding customers of a wide range of financial institutions across multiple countries,” continues the report. “Dyre is a highly developed piece of malware, capable of hijacking all three major web browsers and intercepting internet banking sessions in order to harvest the victim’s credentials and send them to the attackers.” “It is a multi-pronged threat and is often used to download additional malware on to the victim’s computer. In many cases, the victim is added to a botnet which is then used to send out thousands of spam emails in order to spread the threat further afield.” Symantec wrote in a detailed report on Dyre.

The experts revealed that the majority of infection is located in Europe except Russia and Ukraine, where Symantec have discovered the majority of command and control servers are located. The experts also noticed that financial institutions in those regions are targeted by the Dyre malware, a circumstance that led to believe that the threat actors are operating in the same area.

“Based on our monitoring of Dyre activity, the attackers appear to adhere to a five-day working week, with no activity on Saturday and Sunday. Monday is the busiest day in terms of activity. This may be due to backlogs resulting from the weekend break. Activity is measured by counting event updates from C&C servers. In terms of operating hours, activity ranges from 3am to 10pm UTC timing, with most of the updates occurring from 9am to 4pm UTC. Since the attackers appear to be operating in the UTC +2 or UTC +3 time zones, it is possible that the attacks originate in Eastern Europe or Russia, based on the workday pattern observed. While a large amount of Dyre’s C&C infrastructure is located in those regions, a relatively low amount of infections is seen. In addition, financial institutions in those regions are generally not on the target list. One possibility is that the attackers may be reluctant to draw attention” continues Symantec.

The report highlights that Dyre implements several anti-analysis techniques, including Anti-debug, Obfuscation and Anti-emulation. According to the experts at Symantec bad actors used 21 differed IP addresses to run man-in-the-browser attacks on the victims, 14 IP addresses were used to distribute the malicious payload.

Enjoy the report!

Pierluigi Paganini

(Security Affairs – Botnet, Dyre)

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 84

Security Affairs Malware newsletter includes a collection of the best articles and research on malware…

2 hours ago

Security Affairs newsletter Round 563 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best…

2 hours ago

Fintech firm Figure disclosed data breach after employee phishing attack

Fintech firm Figure confirmed a data breach after hackers used social engineering to trick an…

22 hours ago

U.S. CISA adds a flaw in BeyondTrust RS and PRA to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in BeyondTrust RS and…

24 hours ago

Suspected Russian hackers deploy CANFAIL malware against Ukraine

A new alleged Russia-linked APT group targeted Ukrainian defense, government, and energy groups, with CANFAIL…

1 day ago

New threat actor UAT-9921 deploys VoidLink against enterprise sectors

A new threat actor, UAT-9921, uses the modular VoidLink framework to target technology and financial…

2 days ago

This website uses cookies.