Carberp malware source code offered for sale with $50,000 price tag

Includes Chinese-made rootkit module

The source code for the once-mighty Carberp bank Trojan is being offered for sale at an asking price of $50,000 (£33,000) on a criminal forum security firm Trusteer has reported.

Reports of malware source code being offered for sale are extremely rare if they happen at all but perhaps Carberp's star has fallen a little from the days when it was considered a state-of-the-game man-in-the-browser (MitB) menace, particularly for attacks on Facebook users.

According to Trusteer, a forum member named '=Sj=' has pitched its source code, complete with a newly-coded and harder-to-detect Chinese rootkit module, for the eminently reasonable rouble equivalent of half a ton.

If this sounds like a god deal, the firm believes that it might reflect the fact that other forums are offering the same source code for far less, making it a sort of malware fire sale. Russian security research firm Group-IB reports this as being as low as $5,000.

The seller was credible, offering considerable detail on the wares and its capabilities, the firm said. He or she also claims to have connection to Carberp's author.

"We have witnessed past occurrences in which a private group acquired malware source code (such as Citadel), enhanced it, sold variants and offered help and support," commented Trusteer' senior manager, Etay Maor.

"With the current feature set this malware offers, it can easily be configured to target a wide variety of businesses as well as be used for data theft and reconnaissance. It remains to be seen if we are witnessing an attempt to dilute this malware due to internal struggles within the Carberp or buyer groups," he said.

It was possible that the source code would be bought in order to form the core of a new malware family, he suggested.

If that happens, then the bootkit-rootkit functionality will be the major selling point. This claims the rootkit will load reliably the moment the OS starts, in other words before any security programmes fire up. This is not a new feature - all rootkits attempt it by their nature - but its claimed ability to pull off this feat across all versions of Windows, including 8, is sure to interest criminals.

Carberp's fate has been uncertain since the largest gang wielding it were busted in March 2012, resulting in the arrest of eight people accused of involvement. The gang's mistake was to target mostly Russian-speaking consumers, bringing it to the notice of the Russian authorities.

However, not long after Kaspersky Lab announced that the malware, while disrupted, was still being used by other affiliates. Despite that pessimistic news, its importance has faded compared to a growing number of malware competitors even if Group-IB believes that it remains in full development in the Ukrainian and Russian underground.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags TrusteerGroup-IBPersonal Techsecurity

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

John E Dunn

Techworld
Show Comments

Cool Tech

SanDisk MicroSDXC™ for Nintendo® Switch™

Learn more >

Breitling Superocean Heritage Chronographe 44

Learn more >

Toys for Boys

Family Friendly

Panasonic 4K UHD Blu-Ray Player and Full HD Recorder with Netflix - UBT1GL-K

Learn more >

Stocking Stuffer

Razer DeathAdder Expert Ergonomic Gaming Mouse

Learn more >

Christmas Gift Guide

Click for more ›

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Walid Mikhael

Brother QL-820NWB Professional Label Printer

It’s easy to set up, it’s compact and quiet when printing and to top if off, the print quality is excellent. This is hands down the best printer I’ve used for printing labels.

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

David Coyle

Brother PocketJet PJ-773 A4 Portable Thermal Printer

I rate the printer as a 5 out of 5 stars as it has been able to fit seamlessly into my busy and mobile lifestyle.

Featured Content

Product Launch Showcase

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?