Skip to main content

Dyre Banking Trojan

Dyre (also known as Dyreza, Dyzap or Dryza) is a banking trojan that targets payroll systems, cryptocurrency and online banking websites.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Dyre (also known as Dyreza, Dyzap or Dryza) is a banking trojan that targets payroll systems, cryptocurrency and online banking websites.

Threat details

Dyre can bypass SSL, allowing it to intercept HTTP and HTTPS sessions. Like other online banking trojans, it is delivered via spam email containing malicious attachments, as well as being distributed via other malware. Once the malware is installed in the system, it can monitor and take screen shots of browser activities, perform man-in-the-middle attacks via browser injections, steal personal security certificates, private keys, steal online banking credentials, and track the victim’s location through STUN (Session Traversal Utilities for NAT). Dyre will also enrol infected devices into a spam botnet to increase the scale of future spam campaigns.


Remediation advice

To prevent and detect a trojan infection, ensure that:

Remediation steps

Type Step
  • A robust program of education and awareness training is delivered to users to ensure they don’t open attachments or follow links within unsolicited emails.
  • All operating systems, antivirus and other security products are kept up to date.
  • All day to day computer activities such as email and internet are performed using non-administrative accounts.
  • Strong password policies are in place and password reuse is discouraged.
  • Network, proxy and firewall logs should be monitored for suspicious activity.
  • User accounts accessed from infected machines should be reset on a clean computer

Last edited: 17 February 2020 12:42 pm