Showing posts with label Business Email Compromise. Show all posts
Showing posts with label Business Email Compromise. Show all posts

Monday, 28 September 2015

Man Charged Steal $ 600,000 Via E-mail


In the United States a 28-year-old man charged with steal more than $ 600,000 through e-mail and an attempt to similarly $ 1.3 million prize. The man is suspected to have emails sent to companies with payment orders for the finance department.

The emails seem to stop coming to the company and include a PDF document with instructions for payment. To the e-mail appear to have legitimate domain names were registered that looked very much like the domain names of the attacked companies. This type of fraud is called "Business E-Mail Compromise" scam. The suspect was in the crosshairs of the FBI after two businesses were defrauded in this way. Both companies made ​​over $ 100,000. The used PDF files were sent to the accused traced suspect. The suspect is guilty, if to a prison term of up to 30 years and a fine of $ 1 million will be condemned.

Worldwide, there are, according to the FBI by now more than 8,000 companies ripped off in this way, of which 7,000 in the United States. The damage amounted to $ 800 million, again the majority, $ 750 million in the US In addition to the 800 million dollars that the FBI recorded in the first eight months of this year, other investigative agencies have a loss amount of $ 400 million observed, causing total damage at $ 1.2 billion comes out.

Friday, 26 June 2015

Trend Micro: Simple Keylogger Costs Companies Millions


A simple commercial keylogger that is distributed has small and medium businesses worldwide millions of euros cost via e-mail attachments, claims the Japanese anti-virus company Trend Micro. It is the HawkEye keylogger offered on the Internet for a few bucks.

Once active, the keylogger is used to steal passwords from the browser and email client. This data is via e-mail, FTP and web panel sent to the attackers. With the stolen passwords to the email accounts of corporate executives, including the CEO and CFO acquired. Then there via the hijacked email accounts, a payment order sent to the accounting. This scam is also known as "Business Email Compromise" and would have caused worldwide last year to a loss of 216 million dollars.According to the FBI and Secret Service more and more American companies are affected by the fraud. The reason for the investigation services to a warning to deliver.

For the dissemination of the keylogger to send .exe and .zip files that are supposedly an invoice, purchase order or quote. In some cases, the criminals make first contact with the companies. Only after several e-mail exchanges, the keylogger will be sent. According to Trend Micro, the majority of victims of HawkEye in India, followed by Egypt and Iran. These are companies in different sectors, but mainly goods, transportation and manufacturing. It also appears that most companies are accessed via info @ email address.

Trend Micro made ​​a report ( pdf ) on HawkEye which also analyzed two Nigerian cyber criminals using the malware. According to the researchers HawkEye seem a simple keylogger, but is motivated cyber criminals more than sufficient to carry out malware attacks. Also by other security HawkEye was recently investigated as iSight Partners . The research shows that this security be used for the dissemination of keylogger files invoice.exe, payment and purchase slip.exe order.exe. ISight also argues that most victims are in India, but also see a lot of infections in Italy, the United States and Turkey. Furthermore, there are also infections observed in the Netherlands.