Clampi Trojan stealing online bank data from consumers and businesses
LAS VEGAS—Hundreds of thousands of Windows computers are believed to be infected with a Trojan called “Clampi” that has been stealing banking and other log-in credentials from compromised PCs since 2007 …
Context & Ripple Effects
The warning follows an earlier alert about a stealthy Windows virus in January 2008, and confirms that quietly resident credential thieves had become a persistent condition of the Windows installed base rather than a one-off outbreak. Researchers presenting in Las Vegas this week estimate hundreds of thousands of machines have carried the Clampi Trojan since 2007, most of them unaware of it.
What makes Clampi notable is its target set: unlike consumer-data scams, it harvests banking and other log-in credentials from both home users and business PCs, meaning a compromised office machine can hand attackers direct access to corporate funds.
First-order effects
- Consumers and businesses running infected Windows machines must treat every banking and site password entered on those PCs as stolen, since Clampi has been silently capturing credentials for roughly two years.
- Banks face fraudulent-transfer risk on accounts accessed from compromised machines, with business accounts — which typically lack consumer-grade fraud protection — the most exposed.
Second-order effects
- Banks will be pushed toward stronger authentication and transaction controls for online business banking, adding friction for legitimate customers to cut off credential-theft cash-outs.
- Security vendors face pressure to detect long-running, low-profile Trojans like Clampi specifically, because infections persisting since 2007 show signature-based cleanup alone is leaving machines compromised for years.
Third-order effects
- Credential theft from authenticated browsing sessions is consolidating into an industrialized criminal business model, shifting malware economics away from vandalism toward direct financial extraction.
- As long as business computing remains dominated by Windows, the platform's installed base will keep drawing exactly this class of targeted financial malware, forcing banks and software makers to design defenses around the assumption that endpoint machines are compromised.
The trend: Malware is shifting from opportunistic vandalism to patient, financially motivated theft of online-banking credentials, with business Windows machines as the highest-value targets.