How Did Banking Trojans Become a Criminal Market?

TL;DR
Banking Trojans manipulate online banking sessions by hooking browsers, where attackers can bypass SSL protection and alter traffic between victims and financial organizations. Their development evolved from technically demanding, custom-built tools into commercial kits, private malware, and malware-as-a-service, supported by an underground ecosystem that made financial attacks easier to launch, operate, and maintain.
Transcript
Thank you. Hello, everybody. In the next twenty or so minutes, I'd like to take you all on a brief history of financial malware or banking Trojans, and I'd like to take you past some of the most important events and decisions that helped shape the financial malware developments over the past ten years, and that brought us to where we are today with... Read More
Key Insights
- Financial malware is software used by attackers to manipulate commercial or retail online banking sessions. Its purpose is not limited to stealing stored information, because it can interfere directly with communications exchanged between a victim and a financial organization while the banking session is underway.
- The browser is the primary interception point for most banking Trojans. Man-in-the-browser malware hooks into it so attackers can manipulate traffic at a point where the SSL protection that would ordinarily prevent tampering has effectively been bypassed.
- Many financial malware families also create botnets controlled through a central command-and-control server. This reporting and control structure allows criminals to direct infected machines and coordinate the broader attack rather than relying only on isolated malware installations.
- Early online banking attacks demanded strong technical skills because criminals often had to write code and assemble their own operations. Families including Bankbatch, Hackdoor, Limbo, and Nethell emerged during this experimental period, when developers were still determining how such attacks could be run successfully.
- Zeus transformed financial malware into a commercial kit that criminals could buy through underground markets. Customers still had to configure and operate the software themselves, but the packaged product reduced the development burden and helped Zeus gain substantial popularity among attackers.
- SpyEye competed with Zeus by charging less and adopting the Zeus configuration style. Compatibility lowered switching costs because existing attacks could move from a Zeus botnet to SpyEye without modification, although early SpyEye releases were highly unstable before rapid development improved the product.
- Carberp demonstrates that attacking institutions in the criminals' own country can simplify law-enforcement action. When its operators began targeting Russian banks, the investigation became domestic rather than international, and Russian police arrested key members, although remaining participants later allowed Carberp to return.
- Slavik shifted Zeus from public kit sales toward private malware-as-a-service because supporting a criminal crew produced more money and fewer commercial problems. Transferring the public business redirected attention toward his competitor, while Slavik continued developing the software that became peer-to-peer Zeus, also called Game Over Zeus.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: What is financial malware and what does it target?
Financial malware, also called a banking Trojan, is a malware family used to manipulate online banking sessions involving commercial or retail customers. Rather than merely observing communications, it can interfere with traffic exchanged between a victim and a financial organization. Many such programs also report to command-and-control infrastructure, allowing attackers to organize infected computers as a botnet and direct the operation centrally.
Q: How do banking Trojans bypass SSL protection?
Most banking Trojans use a man-in-the-browser approach. They hook into the victim's browser because that location lets them manipulate communications after reaching a point where SSL no longer prevents tampering. The malware can therefore alter traffic passing between the financial organization and the victim during an online banking session, even though the connection itself uses SSL protection.
Q: How did cybercrime kits change online banking attacks?
Cybercrime kits made banking attacks accessible to criminals who were not expert programmers. Before kits appeared, running a successful operation required substantial technical skill, including the ability to develop and write code. A packaged product such as Zeus could instead be purchased through the underground market, then configured and operated by the buyer, lowering the technical barrier to launching an attack.
Q: Why did SpyEye compete effectively with Zeus?
SpyEye was designed specifically to take market share from Zeus. Its author charged far less than the price of a fully equipped Zeus kit and adopted the Zeus configuration style. That compatibility meant customers could transfer an existing Zeus-based attack to SpyEye without modifying it. Early SpyEye versions were unstable, but a rapid development pace quickly improved the software and strengthened its competitive position.
Q: What lesson did the Carberp arrests provide?
Carberp showed why criminals risk greater exposure when they attack banks in the country where they live. Its operators initially targeted banks in Northern Europe but later attacked Russian institutions. That choice changed the law-enforcement challenge from an international investigation into a more straightforward domestic operation, helping Russian police arrest key participants. Carberp nevertheless returned because some members escaped imprisonment or fled.
Q: Why was the Sinowal group unusual among malware operators?
Sinowal, also known as Torpig, was unusual because it remained a closed group whose members were never successfully identified. Before investigators could determine who was behind it, the operators shut down their activities and disappeared. That outcome contrasted with the behavior of many other actors described in the history, who continued operating long enough to attract law-enforcement action and eventually encounter serious consequences.
Q: Why did Slavik stop selling Zeus as a public kit?
Slavik concluded that supplying Zeus to the JabberZoos crew as a service generated more money than selling kits publicly. Kit sales also required customer support, suffered from piracy, and made him a visible supplier whom law enforcement could target. By transferring the kit business to SpyEye's author, he redirected public attention while continuing private development for the crew that used his software.
Q: What happened after the Zeus source code leaked?
The Zeus source-code leak made banking malware broadly available without the previous purchase requirement. Slavik had distributed the code not only to his principal competitor but also to major customers who might not want to work with that competitor. After at least one recipient failed to keep it private, anyone could download the source, compile it, and begin using the resulting banking Trojan.
Summary & Key Takeaways
-
Financial malware targets commercial or retail online banking sessions, commonly through man-in-the-browser techniques. By hooking the browser, malware can manipulate traffic after SSL protections have been bypassed. Many banking Trojans also connect infected machines to centralized command-and-control infrastructure, creating botnets that attackers can direct while an operation is active.
-
Early financial malware required attackers to possess significant technical and programming ability. The arrival of Zeus as a commercial cybercrime kit lowered that barrier by giving customers malware they could purchase, configure, and operate. SpyEye later challenged Zeus through lower pricing, configuration compatibility, and rapid improvements after initially unreliable releases.
-
The market eventually expanded beyond packaged malware into private tools and malware delivered as a service. Slavik stopped publicly selling Zeus after recognizing that supplying a criminal crew could be more profitable and less troublesome. The later Zeus source-code leak made the software broadly accessible and enabled others to compile and use it freely.
Read in Other Languages (beta)
Share This Summary π
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity π






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator