Ice Ice Baby Trojan isn't a plain vanilla threat

happygeek 0 Tallied Votes 410 Views Share

All right stop, collaborate, and listen. A new variant of the ZeuS financial malware platform known as Ice. This baby Trojan spawned from the original Ice IX is targeting bank customers on both sides of the pond. Here in the UK the 'big three' telecommunications providers are where it is flowing like a harpoon, daily and nightly. One thing is for sure, this ain't no vanilla ice attack.

OK, rubbish pop rap references apart, this is actually quite a serious deal. The new Ice TX configurations are apparently not only stealing bank account data, as if that weren't bad enough. but also actively capturing telephone account information about BT, Sky and TalkTalk customers as well.

Why is this such a big deal? I will let Amit Klein, CTRO at banking security vendor Trusteer, explain: "This allows attackers to divert calls from the bank intended for their customer to attacker controlled phone numbers. I believe the fraudsters are executing fraudulent transactions using the stolen credentials and redirecting the bank's post-transaction verification phone calls to professional criminal caller services (discussed in a previous Trusteer blog) that approve the transactions."

Indeed, in one Ice TX attack intercepted by Trusteer, security researchers were able to see how the Trojan first steals the user ID and password of the victim, followed by memorable information and date of birth before then grabbing the account balance of the by now compromised bank account.

What happens next is the interesting, and worrying, bit though. This particular Ice TX configuration will ask the user to update their telephone contact numbers along with the company providing those telephone services. The telephone account number is also requested, suggesting that the banking anti-fraud detection system has malfunctioned in connection with the landline supplier and the number is needed to verify the identity of the account holder. This is dangerous in the extreme as this account number is certainly not the kind of information that would normally be known by anyone other than the customer and service provider. Yet once it has been compromised the attackers are able to modify the victim's phone service settings.

Amit Klein takes up the story again: "Fraudsters are increasingly turning to these post-transaction attack methods to hide fraudulent activity from the victim and block email and phone communication from the bank. This allows attackers to circumvent security mechanisms that look for anomalies once transactions have already been executed by the user."

Dani AI

Generated

A compact expert addendum that clarifies the risk and gives practical next steps.

This Ice family (Ice IX and offshoots) is a ZeuS-derived banking trojan that mixes browser form‑grabbing / page injection with social engineering to harvest telephone‑account identifiers as well as credentials. That mix is what makes recovery harder: attackers can both hide fraudulent activity inside the browser and then try to capture the phone channel banks use for confirmation. Kaspersky Securelist analysis and industry reporting documented these behaviours. (See also the reporting summarizing the Trusteer research.) Dark Reading

On ’s point about browser control: yes, browser control (man‑in‑the‑browser / form‑grab) is the technical enabler. However, the campaign pairs that capability with in‑page dialogs and prompts that ask for carrier-specific secrets (account numbers, PINs, etc.) so criminals can social‑engineer carriers or perform port/SIM‑style attacks to intercept verification calls. Telecom account hijack techniques are a well‑documented method used to bypass phone/SMS checks. See Trusteer coverage and the FBI/IC3 guidance on SIM/port‑out threats. Help Net Security · FBI IC3 PSA on SIM swap

Practical checklist (apply immediately if compromise is suspected):

  • Disconnect the infected machine from the network.
  • From a known‑clean device or landline, contact the bank and telecom: ask the bank to place a fraud alert/freeze and ask the carrier to add a port‑out/blocking lock and change any carrier PINs. (Do this by calling official support numbers, not via links the infected PC shows.)
  • Change banking and email passwords only from a clean device; remove SMS 2FA where possible and move to app‑based or hardware tokens.
  • Scan with up‑to‑date AV plus a behavior/second‑opinion tool; for full assurance back up essential data and reinstall the OS from known‑good media. If unsure, get professional incident help. (Vendor analyses explain removal and detection approaches.) Kaspersky Securelist · FBI IC3 PSA

Longer term, banks and carriers should stop relying on SMS or carrier‑secrets alone for transaction authorization, require stronger carrier protections (port locks, mandatory customer PINs), and push hardware or app‑based MFA; coordinated takedowns and these defensive controls remain the right strategy against persistent Zeus‑family variants. See Europol’s analysis of Zeus/Ice‑family impact for context. https://www.europol.europa.eu/iocta/2015/malware.html

(Added to expand ’s warning and to respond to with concrete, step‑by‑step mitigation.)

Member Avatar for Member #949455
Member #949455

Why is this such a big deal? I will let Amit Klein, CTRO at banking security vendor Trusteer, explain: "This allows attackers to divert calls from the bank intended for their customer to attacker controlled phone numbers. I believe the fraudsters are executing fraudulent transactions using the stolen credentials and redirecting the bank's post-transaction verification phone calls to professional criminal caller services (discussed in a previous Trusteer blog) that approve the transactions."

After reading what you wrote.

I mean the only way for this malware to work is to control the browser that you are using.

It's really hard to notice this virus unless you have a anti-virus/anti-adware installed.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.