Hacker Halted 2011 September 26, 2011

Malware-retooled Just wanted to let everyone know that I will be presenting at Hacker Halted this year. The topic is going to be an interesting one. I would encourage everyone to attend if they can.



Crimeware authors are leveraging the release of source to further develop their already sophisticated and well developed threats as well as add modularity and functionality to their software. In addition the release of Zeus and TDL3 source adds to the wealth of information already available further lowering the entry barrier for developers and price point for would be criminals looking to enter the malware market space. Zeus, SpyEye, (and others like them) are tools that are built specifically to target the financial industry, whereas Sunspot is a general purpose tool that modifies specifically to target banks. This is significant because tools and techniques that are built to detect the former do not work with the latter. Tracking these trends can be accomplished by leveraging classification and clustering models that are built on Behavioral analysis tools.