Kronos (malware)

From HandWiki
Short description: Form of trojan or malware

Kronos was a type of banking malware first reported in 2014. It was sold for $7,000.[1]

It was developed as a followup to the UPAS Kit which has been released in 2012.[2]

Similar to Zeus,[3] it was focused on stealing banking login credentials from browser sessions via a combination of keylogging and web injection.[4] In 2015, its attacks were focused on British banks.[1][2]

In August 2017, British security researcher Marcus Hutchins (aka 'MalwareTech'), previously notable for his involvement stopping the May 2017 WannaCry ransomware attack,[5] was arrested by the FBI whilst visiting the United States.[6] He was alleged to have created the software in 2014, and to have sold it in 2015 via the AlphaBay forums.[7][8] Hutchins later admitted to being paid to work on Kronos and its predecessor UPAS Kit (named after the toxic Upas tree) as the main developer between 2011 and spring 2015.[2]

References

  1. 1.0 1.1 Kessem, Limor (October 2, 2015). "UK Banks Hit With New Zeus Sphinx Variant and Renewed Kronos Banking Trojan Attacks". https://securityintelligence.com/uk-banks-hit-with-new-zeus-sphinx-variant-and-renewed-kronos-banking-trojan-attacks/. 
  2. 2.0 2.1 2.2 Greenberg, Andy (12 May 2020). "The Confessions of Marcus Hutchins, the Hacker Who Saved the Internet". Wired. https://www.wired.com/story/confessions-marcus-hutchins-hacker-who-saved-the-internet/. Retrieved 13 May 2020. 
  3. "Overview of the Kronos banking malware rootkit". September 24, 2014. https://www.lexsi.com/securityhub/overview-kronos-banking-malware-rootkit/?lang=en. 
  4. Constantin, Lucian (14 July 2014). "New banking malware 'Kronos' advertised on underground forums". http://www.pcworld.com/article/2453820/new-banking-malware-kronos-advertised-on-underground-forums.html. Retrieved 4 August 2017. 
  5. Gibbs, Samuel (22 May 2017). "WannaCry hackers still trying to revive attack says accidental hero". The Guardian. https://www.theguardian.com/technology/2017/may/22/wannacry-hackers-ransomware-attack-kill-switch-windows-xp-7-nhs-accidental-hero-marcus-hutchins. 
  6. McGoogan, Cara (4 August 2017). "WannaCry hero Marcus Hutchins could face 40 years in US prison". https://www.telegraph.co.uk/technology/2017/08/03/fbi-arrests-wannacry-hero-marcus-hutchins-las-vegas-reports/. Retrieved 4 August 2017. 
  7. Cox, Joseph (August 3, 2017). "Kronos Indictment R". (independent journalist). https://www.documentcloud.org/documents/3912524-Kronos-Indictment-R.html. 
  8. Kerr, Orin (3 August 2017). "The Kronos indictment: Is it a crime to create and sell malware?". https://www.washingtonpost.com/news/volokh-conspiracy/wp/2017/08/03/the-kronos-indictment-it-a-crime-to-create-and-sell-malware/. Retrieved 4 August 2017.