30 July 2015

Cat pics prove hazardous to online bank accounts

04 March 2014  |  6352 views  |  3 cat

Crooks are taking advantage of one the Internet's key weaknesses - a fondness for cat pictures - to infect computers with banking malware, according to Trend Micro.

The Zbot malware uses steganography - the practice of concealing a message within something else - to hide configuration files in images of cats and sunsets, says Trend Micro in a blog post.

Zbot downloads a Jpeg file with an image containing a hidden list of banks from around the world to monitor. If a victim visits one of the banks, the malware jumps into action and steals user credentials.

Image appended with the list of targeted institutions

The attack also downloads other malware onto the system which removes the X-Frames-Options HTTP header from sites the user visits, allowing them to be displayed inside a frame, enabling clickjacking attacks.

Comments: (3)

Andrew Smith - CloudZync - London | 05 March, 2014, 12:33

I think we need to report these types of stories more accurately as this makes it seem a simple picture could put your PC at risk, when in reality it does nothing. The danger is the malware you download and execute that then uses those pictures as a configurable source to attack. This is hardly a new story either....

Be the first to give this comment the thumbs up 0 thumb ups! (Log in to thumb up)
Matt White - Finextra - Toronto | 05 March, 2014, 14:20

Bit of a catty comment.

1 thumb up! 1 thumb up! (Log in to thumb up)
Andrew Smith - CloudZync - London | 05 March, 2014, 15:14

@Matt I know, bit of a cat-astrophe

Be the first to give this comment the thumbs up 0 thumb ups! (Log in to thumb up)
Comment on this story (membership required)
Log in to receive notifications when someone posts a comment

Finextra news in your inbox

For Finextra's free daily newsletter, breaking news flashes and weekly jobs board, sign up now.

Related blogs

Create a blog about this story (membership required)

Related stories

27 February, 2014
31 January, 2014
20 January, 2014
06 January, 2014

Top topics

Most viewed Most shared
Visa confirms Visa Europe acquisition talk...
9207 views comments | 16 tweets | 23 linkedin
Square reportedly files for IPO
6408 views comments | 16 tweets | 13 linkedin
Banks lag manufacturers and telcos in race...
6322 views comments | 28 tweets | 15 linkedin
Wells Fargo creates innovation group
5879 views comments | 15 tweets | 9 linkedin
BNP Paribas explores the blockchain; SocGe...
5750 views comments | 12 tweets | 15 linkedin

Featured job

to $120K base, double OTE, benefits
New York City, NY or Boston, MA (USA)

Find your next job