Showing posts with label Banking Trojan. Show all posts
Showing posts with label Banking Trojan. Show all posts

Thursday, 23 July 2015

Criminals Use Malware To Empty ATMs


In the first months of this year, criminals in four European countries malware used to empty the contents of ATMs. These are so-called 'cash out' or 'jackpot ting' attacks, reports the European ATM Security Team (EAST) in a new report ( pdf ).

Which countries will be concerned and how many do not know when the attack was captured late EAST. Malware to empty with ATMs is not new and was last year for the first time in Western Europe discovered . Criminals with physical access to the machine and then install the malware via a USB connection or CD-ROM. Through the malware and entering a special key combination can then be emptied the contents of the cash cassettes. Late last year, however, there were also discovered attacks in Russia where attackers remote ATMs with malware had infected by first banks to attack .

Most countries had so far mainly due to skimming, although seven countries recorded a decline in the number of skimming incidents and two countries saw an increase. There is also avoid a growing trend skimmers countries with an EMV chip. The greatest damage was skimming through this years ago in Indonesia, followed by the United States and the Philippines. The data from the EAST report come from 19 countries in the Single Euro Payments Area (SEPA) and two non-SEPA countries.

Wednesday, 17 June 2015

G Data: Attack Bundestag With Financial Malware



During the attack on the network of the German Bundestag last week, performed financial malware is used. This was reported by the German anti-virus company G Data that has studied the attack. At present it is not clear whether it is a new attack, or a continuation of the attacks in late May 2015 came to light.

According to the researchers there discovered the last attack of the Swatbanker banking Trojan used. This is a Trojan horse that is specifically designed to steal money from online bank accounts, although it can get other information. Research into the configuration files in the malware has made it clear that the administrators of the botnet Swatbanker between 8 and 10 June new filter functions have applied for the domain "bundestag.btg". This is the URL of the intranet of the Bundestag.

Once active malware can all data entered into forms, such as user names and passwords, as well as data from the browser to send the attackers. Swatbanker spreads through e-mails that appear to come from German banks and telecom providers."Looking at the first analyzes, it seems to be an attack with criminal intent. But we can not exclude other motives and the attackers have copied the behavior of criminals to disguise their true intentions," says Ralf Benzmüller , head of G Data Security Labs.

Tuesday, 3 March 2015

Anti-virus company: Europol Operation Failed Against Botnet


The operation against the Ramnit botnet that Europol several European investigative services and security last week performed partly failed, causing hundreds of thousands of computers controlled by cybercriminals, according to the Russian anti-virus company Doctor Web.

In the operation were seized hundreds of domains that the botnet used to communicate with infected computers, as well as different servers. The Ramnit malware did over a period of almost five years in total to infect 3.2 million computers. The last half year were approximately 500,000 computers have been infected with the malware.

Doctor Web suggests that there are several variations of Ramnit are active, including one which since September 2011 has been announced. This version can steal all kinds of passwords and FTP programs would have on hundreds of thousands of computers are active every day. "Despite the message in the media about a successful operation against the Ramnit botnet, our analysts have no decrease seen botnets that monitors the anti-virus laboratory," the anti-virus company.

According to researchers from the virus fighter would definitely twelve Ramnit botnets operate. Two of these botnets exist together from more than 500,000 infected computers. "The figures show that the parties behind the operation to destroy the botnet Ramnit evidently not been able to turn off all servers of this botnet," as the researchers conclude whatsoever.

Thursday, 26 February 2015

Virus Switched On Millions Of PCs From Windows Update


The Ramnit botnet that this week by Europol, investigative services, Microsoft and security from the air was removed the last 5 years more than 3 million computers Windows Update, Windows Firewall, Windows Defender, User Account Control and the virus off, leaving the machines did not receive important updates and risked getting infected by even more malware.

Ramnit first appeared in 2010. The malware is designed to steal passwords and data for Internet banking. Also, .exe virus, .dll- and .html files on hard drives and connected storage devices infect. Once activated switches the kinds of security measures in Windows as well as the present virus. Ramnit above used a special blacklist with more than 300 different anti-virus programs.

The last time the virus would only disable Microsoft virus scanners. The software giant detected the last six months, some 500,000 computers were infected with Ramnit. Since this week the cyber criminals behind the botnet would no longer be able to communicate with the infected computers. The infection and custom settings are still active.

Virus scanning and removal tools could, however, detect and remove malware. Microsoft recommends that users, therefore, to perform a virus scan regularly. In addition, it is recommended to be careful when opening emails and messages on social media from unknown users and software only download from the website of the supplier. In this way, new infections can be prevented.

Hashes:
b87dda7ab5ff13248e3c084c63d02b4a
4390dec38fefb2f7197b6b5cd3f7ab30
69412c0433d966b49795fa10bb7387ed
72609754b056fe8793fb848fe0167112

Wednesday, 25 February 2015

Large Botnet Achieved By Europol In The Air


Europol has partnered with European investigation services a large botnet off the air that had infected 3.2 million computers worldwide. It involves Ramnit botnet that for years was active and on infected computers include passwords booty made ​​and other data.

Computers were infected by opening links in spam emails and visiting infected websites. Ramnit is also a so-called "file infector" who .exe, .dll- and .html files on hard drives and connected storage devices infected. Once a computer became infected malware added the infected code in these files, and as soon as they were started spreading the infection further. Also were found public FTP servers that were used for distributing Ramnit.

In addition to investigative agencies from the Netherlands, Italy, Germany and Britain Europol coordinated the operation with Microsoft, Symantec and Anubis Networks . During the operation of the botnet Command & Control servers were turned off, and the 300 domains that were used to control infected computers.

"This successful operation demonstrates the importance of cooperation between international investigative agencies and private industry in combating cybercrime. We will remain committed to disable botnets and disrupting the infrastructure used by criminals for cyber crime," said Wil van Gemert, Deputy Director of Europol. Microsoft and Symantec have now been delivered solutions to remove the malware from infected computers.

Tuesday, 17 February 2015

Banks Hacked And Robbed By Missing Word Updates


About a hundred banks and financial institutions for a period of two years by cyber criminals hacked and robbed because security updates for Microsoft Word had not been installed. According to a published today report of the Russian antivirus company Kaspersky Lab, the gang of cyber criminals gave the name Carnabak. This is the same gang that late last year by the Dutch Fox-IT and the Russian Group-IB was unmasked .

This weekend was the New York Times all with a message about the gang. It stated that Dutch banks had been targeted.Something later by both the Dutch banks as Kaspersky Lab was denied. In an old version of the report, which include Computer Emergency Reponse Teams (CERTs) was dispersed, the Netherlands was mentioned. However, it was in fact a false positive.

Although the New York Times Kaspersky had received a report that newer Netherlands ceased, it still used the information from the old report, says Jornt van der Wiel, analyst at Kaspersky Lab. Another detail that was highlighted in the media is wrong to use recording software. The gang has monitored no security cameras inside the attacked banks, but made ​​via software images from the desktop. This gave insight into the methods and processes within the banks.

It now appeared online report also shows how the attackers went to work. Bank employees who sent emails with Word documents, and in some cases, RAR files containing CPL files. However, there were mainly used Word documents, Van der Wiel. The documents were abuse of leaks in 2012, 2013 and 2014 all were patched by Microsoft. Patches that were missing on the attacked systems. There was in this operation no zero-day vulnerabilities. The advice given to both consumers and businesses, namely installing security updates timely, was not followed by the banks.

Once bank employees with a vulnerable version of Microsoft Office documents of the attackers opened there was malware installed on the system. In some cases, were also used RAR files there, including a CPL file. CPL (Control Panel) files are used for configuration Protect. The programs in the Control Panel as 'System', 'Printers' and 'Programs and Features', all CPL files. They are also used as malware. Furthermore, Kaspersky Lab says that there may be traces of classic drive-by download attacks are detected, in which bank staff when visiting a Web site became infected, but this is not confirmed yet.

Once the attackers had access to the system was installed additional software, such as the Ammyy Remote Administration Tool. Probably the attackers used this tool because it is on a whitelist in many environments. Ammyy gives administrators namely remote access to the computer. Then the attackers tried to steal the credentials of the system. For this, there were internal emails from the infected computers again sent infected Word files. In this way, could be infected, other systems on the network.

Eventually the attackers access to the transaction systems and made the money to other accounts or left-recording infected ATMs. Researchers have one shot where there is to see how someone at night with a bag goes to the ATM of a bank. At exactly 3:00 am spitting automatics the notes from that stopped and taken into the bag by the man.

The damage from the surgery is difficult to determine. Although in the media amounts of $ 1 billion mentioned, this amount is not confirmed. Kaspersky used a calculation method whereby a damage of $ 10 million per bank is used, although this amount is not stolen at all banks. Thus in the report but one victim mentioned that lost $ 10 million and a second bank where 7.3 million dollars were diverted.

Yet Kaspersky multiplied the amount of $ 10 million with 30 affected banks. In addition, there might also be some 30 banks that did not report and the police should also know of some 30 affected banks. For these banks, most of which are located in Russia, $ 10 million was used, eventually yielding an unconfirmed amount of around $ 900 million. The actual damage is probably about $ 300 million or maybe even much lower, Van der Wiel notes. Kaspersky also involves a battle report to hand.

What is certain is that the criminals to strike because the banks did not follow the basic rules for safe Internet, namely the installation of security updates, and do not open unsolicited attachments. Two of the hijacked Russian banks were due to the poor security of their banking license be lost. According to Kaspersky, the attackers are still active.

Monday, 16 February 2015

Gang That Stole Millions From Banks Last Year Already Unmasked


The gang of cyber criminals that this weekend the news was because they enable a billion dollars in banks around the world had been stolen last year by Dutch and Russian security unmasked . From when the published analysis showed that the attacks could have been prevented if the banks had installed security updates for Microsoft Word and employees had opened no exe files that were sent via email.

The Russian anti-virus firm Kaspersky Lab will later today make a report out on the Carnabak gang. The gang was last year in a report by the Delft Fox-IT and Russian Group-IB called "Anunak". The attack that the researchers of the two security companies which took begun infecting the computer of an employee. For example, documents were used in Word installed malware via known vulnerabilities.

If the system of the banks had installed the updates for these vulnerabilities, which since 2012 and 2013 are available, it would fail the attack. Also sent the attackers email attachments with exe files. In case this step was successful was then tried to steal the password of a user with administrator privileges. The next step consisted of getting access to a server.



Through the server password of the domain administrator was compromised. Hereafter all active domain accounts were taken over and monitor the attackers email traffic. The next step in the attack consisted of the compromise of the operator workstations of the bank system. In these systems, recording software was installed to record the process of the workers.Finally, there were changes made in the firewall configuration. Or the gang has adapted the method later applied or other tactics will only become clear once the report of Kaspersky online. but according to Fox-IT Carnabak and Anunak same group.

The examination of the two security companies further revealed that the criminals had access to ATMs and could infect remote malware to record at later times "free" money. The group had access to 50 Russian banks, five payment and sixteen companies. The damage amounted to 14 million dollars, according to the researchers. The attacks were at the time of publication are still going on in the december.

In an update , Fox-IT suggests that a different amount has named Kaspersky because it listed only the direct losses of Russian banks that could be verified. There was also in the report do not include damage caused by intellectual property theft and damage caused by downtime and repairs. Furthermore, Kaspersky Lab reports that banks in Europe and the US have become the target, while not appearing in the research of Fox-IT and Group-IB.

After publication of the report in December, the gang would have scaled back their activities. "The exact reason for this break is unclear, but he was already going for our report," said the researchers. At this time, the group would be not very active."But they can at any time to start again. Another possibility is that they have already started and we have no reports or evidence of their new activities."

Sunday, 15 February 2015

Cyber ​​Criminals Steal Millions From Banks Worldwide



A group of cyber criminals worldwide millions of dollars from more than 100 banks in 30 countries stolen.Most of the affected banks are located in Russia and the US, followed by banks in Germany, Ukraine and China. Dutch banks would not have been a target in contrast to previous reports.

This was discovered by the Russian anti-virus firm Kaspersky Lab on Monday a report on the operation will publish the cybercriminals, but part of all details with the New York Times reported. The Russian virus fighter came the criminals on the track when an ATM in Kiev randomly money bills issued without there was an ATM card in the machine plugged. Research showed that cyber criminals had infiltrated the internal banking network.


By sending infected e-mails, for example, a news item that appeared from a colleague who became infected by staff opened the bank computers. Through these computers knew the attackers to gain access to the systems that used the bank staff for daily transactions and accounting. Through the installed malware was then included the process of the bank employees.

This information used the criminals to pose as bank staff, where there are millions of banks in Russia, Japan, Switzerland and the United States was transferred to accounts in other countries. To include also the money the criminals ruled the ATMs of the bank, so that the expenses banknotes at a certain time. In addition, the money was transferred through online banking systems.

However, the largest amounts were stolen by hacking the accounting systems of the banks and temporarily change the account. For example, a bill of $ 1,000 to $ 10,000 raised, and $ 9,000 was transferred to another bank. The original account holder noticed nothing of this and the bank fraud after discovering some time. Many banks accounts were found to check every 10 hours. Within this time window, the criminals were able to change the accounts and transfer the money.


In total, were attacked according to Kaspersky Lab over a period of nearly two years, more than 100 banks in 30 countries.Which banks will want the anti-virus company can not say. Researchers from the virus fighter would have seen evidence that the gang $ 300 million has been captured and possibly even triple this. This estimate, however, would be impossible to prove because the criminals a limit of $ 10 million per transaction wielded.

Some banks, however, were repeatedly struck. The New York Times reports that most transactions were modest, probably in order not to let the warning systems of the banks go. "If going to the tactics and methods used by the cybercriminals to go unnoticed, this is probably the most sophisticated cyber attack that has taken place so far," said Chris Doggett of Kaspersky Lab.

Kaspersky Lab know that no Dutch bank or banks are affected there as previously reported, on which the article was adapted. In addition, would also no banks in Belgium and Luxembourg have been targeted. In the article by the New York Times, however, still always stated that money from one or more Dutch banks has been stolen. A survey of Kaspersky Lab shows that after Russia and the US banks in Germany, the Ukraine and China are most affected.

According to the virus fighter used the attackers emails with the attached "Carnabak-malware" and emails were also used with exploits. Or were these exploits of unknown leak or leaks which use an update was available is not yet published. However, the attackers would at banks have infected hundreds of computers to find the computer system, which then accesses the transaction systems were obtained.

Kaspersky Lab has also announced that the New York Times, the cooperation between the anti-virus company and the Dutch National High Tech Crime Unit (NHTCU) may have misinterpreted. The Russian virus fighter has information about the case is sent to the NHTCU. Further, the report will tomorrow during Kaspersky Security Analyst Summit (SAS) are presented, together with Peter Zinn of the NHTCU.

Possibly, the US newspaper based on this that Dutch banks have become victims. However, the Netherlands is in the report that tomorrow does not appear in the list of affected countries. Furthermore, Kaspersky Lab that it has no evidence that Dutch financial institutions have fallen victim.