New DNSChanger Trojan variant targets routers

New variant of trojan changes DNS look-up settings on routers, putting any computer on the network at risk of being sent to malicious Web sites.

Secure Computing researchers have discovered a new variant of the DNSChanger Trojan in the wild that attacks routers, meaning any Web surfing computer on that network could be at risk of being redirected to a malicious Web site.

The DNSChanger Trojan changes the DNS settings to point to a host Web site address supplied by the attackers, Sven Krasser, director of data mining research at Secure Computing, said in an interview with CNET on Tuesday.

"Your network is essentially reconfigured to do all the (domain) name resolutions over this malicious name server," he said.

The DNSChanger Trojan is able to access all the settings and functions on the router. It only knows about a few popular router Web interface URLs that it can use to change DNS settings at this time, but that is expected to change and more routers will be affected, according to a Secure Computing blog entry.

The Trojan is believed to be created by the creators of the family of malware called "Zlob," which masquerades as an ActiveX video codec.

A new variant of the DNSChanger Trojan attacks routers so that non-existing domain names are added by the malware. These rogue DNS servers, located in the Ukraine, resolve any domain name you provide and redirect to Web sites that look like the one in this screenshot. Secure Computing
Featured Video
This content is rated TV-MA, and is for viewers 18 years or older. Are you of age?
Sorry, you are not old enough to view this content.

Top 5 Surprise Tech Hits

Sometimes a product may seem like a crazy idea, but it goes on to far exceed expectations. These are the most surprising tech successes.

by Iyaz Akhtar