Almost £600,000 siphoned
By Dan Goodin in San Francisco • Get more from this author
Posted in Crime, 16th November 2009 18:45 GMT
Free whitepaper – Shopping for a secure file transfer solution for retail
A British court has sentenced four men to prison after they admitted they used sophisticated trojan software to steal almost £600,000 from bank accounts and send it to Eastern Europe.
London's Southwark Crown Court on Friday imposed sentences of as much as 4 and a half years on the men. According to IDG News, they used a trojan known as PSP2-BBB to stealthily monitor victims' browsers. It inserted special fields into banking pages that asked for sensitive information and then sent it to the criminals when the user complied.
To give it the pages air of legitimacy, they bore the logo of NatWest, according to other news reports. The gang used a stable of money mules to transfer the funds to countries including Ukraine, which is also the location of a computer server that was used in the scam.
At least 138 banking customers were affected with "just under £600,000 being fraudulently transferred," according to the Press Association. Almost £140,000 was later recouped from Royal Bank of Scotland, NatWest's parent company.
Azamat Rahmanov, 25 of London's Lewisham, received four and a half years and was considered one of the organizers, according to news reports. Shohruh Fayziev, a 23-year-old Uzbekistani who lived in Peckham Rye, Southwark, in south east London, got four years. He was regarded as a "trusted lieutenant."
The remaining two men were the Angolan-born "facilitator" Joao Cruz, 33, of South London, who received three years, and Portuguese Recardo Pereira, 36, of Essex, who was sentenced to 21 months.
UK authorities have hailed the case as the first collaboration between the financial industry and the Police Central e-Crime Unit, which was established earlier this year to crack down on cybercrime. ®
Sunday, 29 November 2009
Smut-ladened spam disguises WoW Trojan campaign
Posted in Malware, 27th November 2009 15:12 GMT
Free whitepaper – A Healthy Prescription for Secure and Compliant File Transfer
A malicious spam campaign that attempts to harvest online game passwords under the guise of messages containing smutty photos is doing the rounds.
The tainted emails have subject line such as "Do you like to find a girlfriend like me?", and an attached archive file called "my photos.rar". The archive contains photos of young Asian women and content that poses as clips from a bongo flick.
The supposed video files actually harboured video files and a password-stealing Trojan called Agent-LVF, which is designed to steal the login credentials of World of Warcraft gamers. Security firm Sophos reckons it's likely the stolen credentials and associated in-game assets will be sold through underground sites, earning hackers a tidy profit in the process.
"A surprising amount of malware is designed to steal registration keys, passwords and data from players of computer games," said a consultant at Sophos. "This isn't just about doing better in a computer game. Criminals are stealing virtual assets like armour, money and weapons to trade for hard cash in the real world.”
More about the threat can be found in a blog posting by Sophos here. ®
Free whitepaper – A Healthy Prescription for Secure and Compliant File Transfer
A malicious spam campaign that attempts to harvest online game passwords under the guise of messages containing smutty photos is doing the rounds.
The tainted emails have subject line such as "Do you like to find a girlfriend like me?", and an attached archive file called "my photos.rar". The archive contains photos of young Asian women and content that poses as clips from a bongo flick.
The supposed video files actually harboured video files and a password-stealing Trojan called Agent-LVF, which is designed to steal the login credentials of World of Warcraft gamers. Security firm Sophos reckons it's likely the stolen credentials and associated in-game assets will be sold through underground sites, earning hackers a tidy profit in the process.
"A surprising amount of malware is designed to steal registration keys, passwords and data from players of computer games," said a consultant at Sophos. "This isn't just about doing better in a computer game. Criminals are stealing virtual assets like armour, money and weapons to trade for hard cash in the real world.”
More about the threat can be found in a blog posting by Sophos here. ®
Web host Daily recovers after Tux-themed defacement
UK-based web host Daily has largely restored services following an apparent hack attack on Thursday that replaced content on some sites it hosts with pictures of cartoon penguins.
The images of Linux penguin Tux parodied the 'hear/see/speak no evil' monkeys". Text included on the defacements claimed the hack in the name of 'Heart_Hunter - TH3_H4TTAB'.
pwned with cartoon penguins
Customers were advised to restore their sites from back-up copies. Daily has begun an investigation into the attack, which bears the hallmarks of a mass defacement. Groups of websites are regularly defaced by TH3_H4TTAB, as defacement archive Zone-H records. In many cases eastern folk music is uploaded onto compromised sites.
A status page on Daily's status site explains "We have received reports this [Thursday] morning of a small number of customer websites having their index or start page replaced with an image and in some cases text as well."
The host completed the restore process by 2100 on Thursday. Daily modified its PHP build as a security precaution. Services were largely restored on Friday but may proceed more slowly than possible after some servers were taken offline in order to mount an ongoing security investigation, a status update from Daily explains:
We are confident there will be no repeat events as all servers are locked down.
Some websites (in particular Database driven sites) will be running at slower speeds as we have taken some web servers from our cluster to carry on with our investigations and diagnosis.
A Reg reader who told us of the hack explained how the attack affected one of the web sites he managed, which was hosted by Daily. "Every file that included 'index' and 'php' in the name - including some buried in a child directory that's invisible to Google were defaced," he explained.
The reader expressed frustration that the attack had taken place. "When you go to great lengths to keep everything secure and then the hosting company lets them through the back door, it doesn't look good," he said. ®
The images of Linux penguin Tux parodied the 'hear/see/speak no evil' monkeys". Text included on the defacements claimed the hack in the name of 'Heart_Hunter - TH3_H4TTAB'.
pwned with cartoon penguins
Customers were advised to restore their sites from back-up copies. Daily has begun an investigation into the attack, which bears the hallmarks of a mass defacement. Groups of websites are regularly defaced by TH3_H4TTAB, as defacement archive Zone-H records. In many cases eastern folk music is uploaded onto compromised sites.
A status page on Daily's status site explains "We have received reports this [Thursday] morning of a small number of customer websites having their index or start page replaced with an image and in some cases text as well."
The host completed the restore process by 2100 on Thursday. Daily modified its PHP build as a security precaution. Services were largely restored on Friday but may proceed more slowly than possible after some servers were taken offline in order to mount an ongoing security investigation, a status update from Daily explains:
We are confident there will be no repeat events as all servers are locked down.
Some websites (in particular Database driven sites) will be running at slower speeds as we have taken some web servers from our cluster to carry on with our investigations and diagnosis.
A Reg reader who told us of the hack explained how the attack affected one of the web sites he managed, which was hosted by Daily. "Every file that included 'index' and 'php' in the name - including some buried in a child directory that's invisible to Google were defaced," he explained.
The reader expressed frustration that the attack had taken place. "When you go to great lengths to keep everything secure and then the hosting company lets them through the back door, it doesn't look good," he said. ®
Thursday, 26 November 2009
Cyber breaches kept secret
By Reuters
25 Nov 2009
Cybercriminals regularly breach computer security systems, stealing millions of dollars and credit card numbers in cases that companies keep secret, said the FBI's top Internet crimes investigator.
For every break-in like the highly publicised attacks against TJX and Heartland Payment, where hacker rings stole millions of credit card numbers, there are many more that never make the news.
"Of the thousands of cases that we've investigated, the public knows about a handful," said Shawn Henry, assistant director for the Federal Bureau of Investigation's Cyber Division. "There are million-dollar cases that nobody knows about."
Companies that are victims of cybercrime are reluctant to come forward out of fear the publicity will hurt their reputations, scare away customers and hurt profits. Sometimes they don't report the crimes to the FBI at all. In other cases they wait so long that it is tough to track down evidence.
"Keeping your head in the sand on filing a report means the bad guys are out there hitting the next guy, and the next guy after that," Henry said.
He said the cybercrime problem has gotten bigger over the past three years because hackers have changed their attack methods as companies have tightened up security.
"It's absolutely gotten bigger, yes, absolutely," he said.
25 Nov 2009
Cybercriminals regularly breach computer security systems, stealing millions of dollars and credit card numbers in cases that companies keep secret, said the FBI's top Internet crimes investigator.
For every break-in like the highly publicised attacks against TJX and Heartland Payment, where hacker rings stole millions of credit card numbers, there are many more that never make the news.
"Of the thousands of cases that we've investigated, the public knows about a handful," said Shawn Henry, assistant director for the Federal Bureau of Investigation's Cyber Division. "There are million-dollar cases that nobody knows about."
Companies that are victims of cybercrime are reluctant to come forward out of fear the publicity will hurt their reputations, scare away customers and hurt profits. Sometimes they don't report the crimes to the FBI at all. In other cases they wait so long that it is tough to track down evidence.
"Keeping your head in the sand on filing a report means the bad guys are out there hitting the next guy, and the next guy after that," Henry said.
He said the cybercrime problem has gotten bigger over the past three years because hackers have changed their attack methods as companies have tightened up security.
"It's absolutely gotten bigger, yes, absolutely," he said.
NIST Director Sees Key Role In Emerging Technologies
By J. Nicholas Hoover
InformationWeek
November 25, 2009
As it takes on research and standardization in the areas of healthcare IT, smart grid, and cybersecurity, the National Institute of Standards and technology has a "critically important" role to play, according to NIST's new director, Patrick Gallagher.
A 16-year NIST veteran and former deputy director, Gallagher's appointment as confirmed by the Senate earlier this month. "What you're going to see is a small parade of things that will become critically important to solving government or national problems where we'll have to tackle them," Gallagher said in an interview.
IT has become an important focus of NIST's efforts. While better known for its work in physics and science -- the agency sets official time in the United States -- NIST's IT work is every bit as significant, Gallagher says. The agency's IT Laboratory accounts for much of the institute's overall lab budget.
NIST, which was given some authority over smart grid standards in 2007, in September released a framework and road map for smart grid interoperability. NIST recently held the first meeting of the Smart Grid Interoperability Panel, which will help set standards. It's a pressing, and challenging, task given that government and private utilities are expected to spend $8.1 billion on smart grid projects over the next three years as part of the American Recovery and Reinvestment Act.
InformationWeek
November 25, 2009
As it takes on research and standardization in the areas of healthcare IT, smart grid, and cybersecurity, the National Institute of Standards and technology has a "critically important" role to play, according to NIST's new director, Patrick Gallagher.
A 16-year NIST veteran and former deputy director, Gallagher's appointment as confirmed by the Senate earlier this month. "What you're going to see is a small parade of things that will become critically important to solving government or national problems where we'll have to tackle them," Gallagher said in an interview.
IT has become an important focus of NIST's efforts. While better known for its work in physics and science -- the agency sets official time in the United States -- NIST's IT work is every bit as significant, Gallagher says. The agency's IT Laboratory accounts for much of the institute's overall lab budget.
NIST, which was given some authority over smart grid standards in 2007, in September released a framework and road map for smart grid interoperability. NIST recently held the first meeting of the Smart Grid Interoperability Panel, which will help set standards. It's a pressing, and challenging, task given that government and private utilities are expected to spend $8.1 billion on smart grid projects over the next three years as part of the American Recovery and Reinvestment Act.
Security Is Chief Obstacle To Cloud Computing Adoption, Study Says
By Tim Wilson
DarkReading
Nov 25, 2009
Nearly half of organizations say they have no plans to use any cloud computing technologies in the next year -- and security concerns are the chief reason why.
That's the conclusion of a survey that will be published next month by Launchpad Europe, a company that helps emerging firms with global business expansion.
In the survey, 49.5 percent of businesses said they are not using or planning to use any cloud technologies within the next 12 months. Of that group, 50 percent cited "security concerns" as the primary reason.
"Budgetary restraints" was the second-biggest reason for avoiding the cloud -- 21.4 percent of respondents said tight budgets precluded them from migrating to cloud-based services. Less than 5 percent cited a lack of available cloud technology to meet their particular needs.
The results suggest security eclipses most other criteria when organizations are considering cloud services vendors, Launchpad Europe said. Thirty-eight percent of respondents said their top priority when considering cloud vendors was "security of the cloud infrastructure."
DarkReading
Nov 25, 2009
Nearly half of organizations say they have no plans to use any cloud computing technologies in the next year -- and security concerns are the chief reason why.
That's the conclusion of a survey that will be published next month by Launchpad Europe, a company that helps emerging firms with global business expansion.
In the survey, 49.5 percent of businesses said they are not using or planning to use any cloud technologies within the next 12 months. Of that group, 50 percent cited "security concerns" as the primary reason.
"Budgetary restraints" was the second-biggest reason for avoiding the cloud -- 21.4 percent of respondents said tight budgets precluded them from migrating to cloud-based services. Less than 5 percent cited a lack of available cloud technology to meet their particular needs.
The results suggest security eclipses most other criteria when organizations are considering cloud services vendors, Launchpad Europe said. Thirty-eight percent of respondents said their top priority when considering cloud vendors was "security of the cloud infrastructure."
Metasploit releases IE attack, but it's unreliable
By Robert McMillan
IDG News Service
November 25, 2009
Developers of the open-source Metasploit penetration testing toolkit have released code that can compromise Microsoft's Internet Explorer browser, but the software is not as reliable as first thought.
The code exploits an Internet Explorer bug that was disclosed last Friday in a proof-of-concept attack posted to the Bugtraq mailing list.
That first code was unreliable, but security experts worried that someone would soon develop a better version that would be adopted by cyber-criminals.
The original attack used a "heap-spray" technique to exploit the vulnerability in IE. But for a while Wednesday, it looked as though the Metasploit team had released a more reliable exploit.
They used a different technique to exploit the flaw, one pioneered by researchers Alexander Sotirov and Marc Dowd, but Metasploit eventually pulled its code
IDG News Service
November 25, 2009
Developers of the open-source Metasploit penetration testing toolkit have released code that can compromise Microsoft's Internet Explorer browser, but the software is not as reliable as first thought.
The code exploits an Internet Explorer bug that was disclosed last Friday in a proof-of-concept attack posted to the Bugtraq mailing list.
That first code was unreliable, but security experts worried that someone would soon develop a better version that would be adopted by cyber-criminals.
The original attack used a "heap-spray" technique to exploit the vulnerability in IE. But for a while Wednesday, it looked as though the Metasploit team had released a more reliable exploit.
They used a different technique to exploit the flaw, one pioneered by researchers Alexander Sotirov and Marc Dowd, but Metasploit eventually pulled its code
Subscribe to:
Posts (Atom)