Showing posts with label Infected Emails. Show all posts
Showing posts with label Infected Emails. Show all posts

Thursday, 23 July 2015

Criminals Use Malware To Empty ATMs


In the first months of this year, criminals in four European countries malware used to empty the contents of ATMs. These are so-called 'cash out' or 'jackpot ting' attacks, reports the European ATM Security Team (EAST) in a new report ( pdf ).

Which countries will be concerned and how many do not know when the attack was captured late EAST. Malware to empty with ATMs is not new and was last year for the first time in Western Europe discovered . Criminals with physical access to the machine and then install the malware via a USB connection or CD-ROM. Through the malware and entering a special key combination can then be emptied the contents of the cash cassettes. Late last year, however, there were also discovered attacks in Russia where attackers remote ATMs with malware had infected by first banks to attack .

Most countries had so far mainly due to skimming, although seven countries recorded a decline in the number of skimming incidents and two countries saw an increase. There is also avoid a growing trend skimmers countries with an EMV chip. The greatest damage was skimming through this years ago in Indonesia, followed by the United States and the Philippines. The data from the EAST report come from 19 countries in the Single Euro Payments Area (SEPA) and two non-SEPA countries.

Wednesday, 11 March 2015

Cybercriminals Steal 491,000 Dollars Through Infected Email


Cyber ​​criminals have to steal 491,000 dollars know of an American town in Florida by infected e-mail attachments to multiple officials, different ones also opened the file. The infection started when an officer opened the first infected email. Similar messages were then sent to other officials, who also opened the attachment. "They thought they received a file that they had to open," said City Manager Jim Hanson opposite the Florida Times Union .

The malware sent the login details for online banking back to the cybercriminals. With this data, the attackers knew then gain access to the online bank account and made 491,000 dollars to an account at Deutsche Bank. "Our employees were within 30 minutes by what had happened," said Hanson. The incident took place on Friday, February 13th, but has only now become known.

After workers robbery on Friday had discovered was called immediately the bank to reverse the transaction. On Tuesday, the bank could reverse the transaction and received the town of about 8,400 residents returned the money, let First Coast News know. According to Hanson, measures have been taken to tighten security. "One lesson we have learned is that your employees have to learn to not open an attachment unless that is expected, even if you think you know the sender," Hanson says. "It may just be a virus."

Tuesday, 10 March 2015

Crypto Locker Infected 200 Computers From VU University


The Crypto Locker ransomware has 200 computers of the VU University Amsterdam (VU) infected as a spokeswoman for the university. "The Crypto Locker Virus haunts on our network," said Aukje Scoop. Twitter posted Rickey Gevers a screenshot of the warning was distributed among staff and students. The damage was due to a good backup strategy, however, are minimal. The malware spreads via email attachments and encrypt files on computers for ransom. To put the impact of ransomware to counteract the VU network decided this weekend to "read-only".

Scans performed at the IT department were discovered last week several infected workstations. Once there was an infection detected, the computer and the corresponding account temporarily blocked. The malware was removed and a backup of the evening returned it, then the computer and the account were released. Because the VU backing up the harm or risk of data loss are minimal. There were no students or employees have come forward that have been lost by the ransomware files.

Last weekend decided the technical department to put the network on read-only, so that the virus could not do his job. "The IT department had more clout to clean everything," Scoop notes. At the VU is a lot of work with group drives, where students store their documents. "Now it's wait and see how it is spread. The virus mutates continuously. Our IT department is aware that it can emerge in other places." At 200 computers Crypto Locker was eventually found.

Emails

"The complicated is that the virus ever mutates. In the beginning was warned mails from unknown senders or stranger left. But it now seems also that it can attach to emails from colleagues. Why is continuously scanned . It is therefore not sufficient to keep only foreign mails outside, because it seems to be mutated itself. "

It is currently unclear whether the students or employees who were initially opened the infected emails. When the first infections through Crypto Locker emerged the university decided to warn in different ways for the ransomware. "It is very much shut out by the security systems. In an organization such as a university, it is impossible to rule out anything. So there is a balance to be searched."

Virus Scanner

The network has now picked up again in read-only. In addition, the university is also looking forward a new type of virus that may in addition have to go, but the details are not yet known. According Spoon would not get the first time that make VU ransomware. A few months ago would have been some isolated cases. "But when that had no effect and that was resolved pretty quickly."

Tuesday, 17 February 2015

Banks Hacked And Robbed By Missing Word Updates


About a hundred banks and financial institutions for a period of two years by cyber criminals hacked and robbed because security updates for Microsoft Word had not been installed. According to a published today report of the Russian antivirus company Kaspersky Lab, the gang of cyber criminals gave the name Carnabak. This is the same gang that late last year by the Dutch Fox-IT and the Russian Group-IB was unmasked .

This weekend was the New York Times all with a message about the gang. It stated that Dutch banks had been targeted.Something later by both the Dutch banks as Kaspersky Lab was denied. In an old version of the report, which include Computer Emergency Reponse Teams (CERTs) was dispersed, the Netherlands was mentioned. However, it was in fact a false positive.

Although the New York Times Kaspersky had received a report that newer Netherlands ceased, it still used the information from the old report, says Jornt van der Wiel, analyst at Kaspersky Lab. Another detail that was highlighted in the media is wrong to use recording software. The gang has monitored no security cameras inside the attacked banks, but made ​​via software images from the desktop. This gave insight into the methods and processes within the banks.

It now appeared online report also shows how the attackers went to work. Bank employees who sent emails with Word documents, and in some cases, RAR files containing CPL files. However, there were mainly used Word documents, Van der Wiel. The documents were abuse of leaks in 2012, 2013 and 2014 all were patched by Microsoft. Patches that were missing on the attacked systems. There was in this operation no zero-day vulnerabilities. The advice given to both consumers and businesses, namely installing security updates timely, was not followed by the banks.

Once bank employees with a vulnerable version of Microsoft Office documents of the attackers opened there was malware installed on the system. In some cases, were also used RAR files there, including a CPL file. CPL (Control Panel) files are used for configuration Protect. The programs in the Control Panel as 'System', 'Printers' and 'Programs and Features', all CPL files. They are also used as malware. Furthermore, Kaspersky Lab says that there may be traces of classic drive-by download attacks are detected, in which bank staff when visiting a Web site became infected, but this is not confirmed yet.

Once the attackers had access to the system was installed additional software, such as the Ammyy Remote Administration Tool. Probably the attackers used this tool because it is on a whitelist in many environments. Ammyy gives administrators namely remote access to the computer. Then the attackers tried to steal the credentials of the system. For this, there were internal emails from the infected computers again sent infected Word files. In this way, could be infected, other systems on the network.

Eventually the attackers access to the transaction systems and made the money to other accounts or left-recording infected ATMs. Researchers have one shot where there is to see how someone at night with a bag goes to the ATM of a bank. At exactly 3:00 am spitting automatics the notes from that stopped and taken into the bag by the man.

The damage from the surgery is difficult to determine. Although in the media amounts of $ 1 billion mentioned, this amount is not confirmed. Kaspersky used a calculation method whereby a damage of $ 10 million per bank is used, although this amount is not stolen at all banks. Thus in the report but one victim mentioned that lost $ 10 million and a second bank where 7.3 million dollars were diverted.

Yet Kaspersky multiplied the amount of $ 10 million with 30 affected banks. In addition, there might also be some 30 banks that did not report and the police should also know of some 30 affected banks. For these banks, most of which are located in Russia, $ 10 million was used, eventually yielding an unconfirmed amount of around $ 900 million. The actual damage is probably about $ 300 million or maybe even much lower, Van der Wiel notes. Kaspersky also involves a battle report to hand.

What is certain is that the criminals to strike because the banks did not follow the basic rules for safe Internet, namely the installation of security updates, and do not open unsolicited attachments. Two of the hijacked Russian banks were due to the poor security of their banking license be lost. According to Kaspersky, the attackers are still active.

Sunday, 15 February 2015

Cyber ​​Criminals Steal Millions From Banks Worldwide



A group of cyber criminals worldwide millions of dollars from more than 100 banks in 30 countries stolen.Most of the affected banks are located in Russia and the US, followed by banks in Germany, Ukraine and China. Dutch banks would not have been a target in contrast to previous reports.

This was discovered by the Russian anti-virus firm Kaspersky Lab on Monday a report on the operation will publish the cybercriminals, but part of all details with the New York Times reported. The Russian virus fighter came the criminals on the track when an ATM in Kiev randomly money bills issued without there was an ATM card in the machine plugged. Research showed that cyber criminals had infiltrated the internal banking network.


By sending infected e-mails, for example, a news item that appeared from a colleague who became infected by staff opened the bank computers. Through these computers knew the attackers to gain access to the systems that used the bank staff for daily transactions and accounting. Through the installed malware was then included the process of the bank employees.

This information used the criminals to pose as bank staff, where there are millions of banks in Russia, Japan, Switzerland and the United States was transferred to accounts in other countries. To include also the money the criminals ruled the ATMs of the bank, so that the expenses banknotes at a certain time. In addition, the money was transferred through online banking systems.

However, the largest amounts were stolen by hacking the accounting systems of the banks and temporarily change the account. For example, a bill of $ 1,000 to $ 10,000 raised, and $ 9,000 was transferred to another bank. The original account holder noticed nothing of this and the bank fraud after discovering some time. Many banks accounts were found to check every 10 hours. Within this time window, the criminals were able to change the accounts and transfer the money.


In total, were attacked according to Kaspersky Lab over a period of nearly two years, more than 100 banks in 30 countries.Which banks will want the anti-virus company can not say. Researchers from the virus fighter would have seen evidence that the gang $ 300 million has been captured and possibly even triple this. This estimate, however, would be impossible to prove because the criminals a limit of $ 10 million per transaction wielded.

Some banks, however, were repeatedly struck. The New York Times reports that most transactions were modest, probably in order not to let the warning systems of the banks go. "If going to the tactics and methods used by the cybercriminals to go unnoticed, this is probably the most sophisticated cyber attack that has taken place so far," said Chris Doggett of Kaspersky Lab.

Kaspersky Lab know that no Dutch bank or banks are affected there as previously reported, on which the article was adapted. In addition, would also no banks in Belgium and Luxembourg have been targeted. In the article by the New York Times, however, still always stated that money from one or more Dutch banks has been stolen. A survey of Kaspersky Lab shows that after Russia and the US banks in Germany, the Ukraine and China are most affected.

According to the virus fighter used the attackers emails with the attached "Carnabak-malware" and emails were also used with exploits. Or were these exploits of unknown leak or leaks which use an update was available is not yet published. However, the attackers would at banks have infected hundreds of computers to find the computer system, which then accesses the transaction systems were obtained.

Kaspersky Lab has also announced that the New York Times, the cooperation between the anti-virus company and the Dutch National High Tech Crime Unit (NHTCU) may have misinterpreted. The Russian virus fighter has information about the case is sent to the NHTCU. Further, the report will tomorrow during Kaspersky Security Analyst Summit (SAS) are presented, together with Peter Zinn of the NHTCU.

Possibly, the US newspaper based on this that Dutch banks have become victims. However, the Netherlands is in the report that tomorrow does not appear in the list of affected countries. Furthermore, Kaspersky Lab that it has no evidence that Dutch financial institutions have fallen victim.