A new version of the Gameover malware is able to steal online banking credentials and has a kernel-level rootkit that makes it very hard to remove, researchers said.
Gameover is a computer Trojan based on the Zeus banking malware whose source code leaked over the Internet in 2011. Gameover stands apart from other Zeus-based Trojan programs because it uses peer-to-peer technology for command and control instead of traditional servers, making it more resilient to takedown attempts, according to researchers at Sophos.
RELATED STORIES
Espionage Rootkit has Russian Roots
Xtreme RAT Targets Governments
Energy Sector Under Attack
Report: Security Needs Proactive Approach
At the beginning of February, researchers from security firm Malcovery Security, reported a new variant of Gameover was going out as an encrypted .enc file in order to bypass network-level defenses. The latest move from Gameover authors comes from using a kernel rootkit called Necurs to protect the malware’s process from terminating and its files from deletion, Sophos researchers said in a blog post.
The latest Gameover variant is going out through spam emails purporting to come from HSBC France with fake invoices in .zip attachments. These attachments don’t contain the Gameover Trojan program itself, but a malicious downloader program called Upatre which, if run, downloads and installs the banking malware.
If this first stage of the infection is successful, the new Gameover variant attempts to install the Necurs rootkit which operates as a 32-bit or 64-bit driver depending on the Windows version used by the victim. The malware tries to exploit a Windows privilege escalation vulnerability patched by Microsoft in 2010 in order to install the Necurs driver with administrator privileges.
If the system ends up patched and the exploit fails, the malware triggers a User Account Control (UAC) prompt to ask the victim for administrator access. The UAC prompt should look suspicious considering the user opened what he believed to be an invoice, researchers said.
However, if the user confirms the execution anyway or the exploit is successful in the first place, the rogue driver starts protecting the Gameover components.
“The rookit greatly increases the difficulty of removing the malware from an infected computer, so you are likely to stay infected for longer, and lose more data to the controllers of the Gameover botnet,” researchers said.
Zeus and its spin-offs continue to be popular with cybercriminals. A new report from Dell SecureWorks, found Zeus variants accounted for almost half of all banking malware seen in 2013.
In addition to stealing online banking credentials and financial information, bad guys are increasingly using such malware to collect other types of data. Security firm Adallom just found a Zeus variant designed to steal Saleforce.com credentials and scrape business data from the compromised accounts.

