The people who brought the world malicious software that steals credit card numbers from your personal computer and empties bank ATMs of their cash are hiring, and they're advertising online.
Two companies that are hiring -- at least on a contractor basis -- advertise online, said Kevin Stevens, a threat intelligence analyst for SecureWorks, who presented findings on the organizations at the Black Hat cybersecurity conference outside Washington on Monday.
What they are seeking is people who are willing to take malicious code they provide and link it to something that people will click on -- like a picture of Britney Spears getting out of her car. These people then collect a fee for each 1,000 times that the malware is downloaded.
One site, for example, pays $180 for each 1,000 times that malware is downloaded onto a U.S. computer but less for computers elsewhere. It refuses to pay for any downloads to Russian computers, causing Stevens and others to strongly suspect that it, like other similar sites, are based in Russia.
"We pay your wages via the following systems: Fethard, WebMoney, Wire, e-gold, Western Union (WU), MoneyGram, Anelik and ePassporte, and PayPal," the site said.
Stevens said it was impossible to know how many computers were infected via these companies but put the number in the millions.
Security professionals in the audience for Stevens' presentation laughed at times, most likely at how blatant the web sites were. reuters
Showing posts with label cyber crime. Show all posts
Showing posts with label cyber crime. Show all posts
Tuesday, February 2, 2010
Sunday, November 29, 2009
Cyber crime danger
THE Police Force has forecast cyber crimes to increase by 40 to 50 per cent from 2010 to 2012.
Jemesa Lave of the police cyber crime unit said in these two years, it was anticipated that more complicated technological crimes would be perpetrated in Fiji.
Coupled with this, he said was the anticipated shift from conventional criminal operations to cybercrime.
"We need legislation, we need to ensure that standards are put in place to address computer crime issues," Mr Lave said.
He said people needed to be aware that computer crimes knew no borders. Fiji Times
Jemesa Lave of the police cyber crime unit said in these two years, it was anticipated that more complicated technological crimes would be perpetrated in Fiji.
Coupled with this, he said was the anticipated shift from conventional criminal operations to cybercrime.
"We need legislation, we need to ensure that standards are put in place to address computer crime issues," Mr Lave said.
He said people needed to be aware that computer crimes knew no borders. Fiji Times
Tuesday, November 17, 2009
Cyber laws must punish individuals not society: specialist
SHARM EL-SHEIKH, Egypt (AFP) - Laws regulating cybercrimes must target individuals and not society as a whole, an IT specialist told an Internet governance forum at the Egyptian resort of Sharm el-Sheikh on Tuesday.
Gisele Da Silva Craveiro from the University of Sao Paolo in Brazil said the broad nature of cyberlegislation leaves it open to abuse by authorities.
"Definitions for cybercrimes can be so broad as to fit everything... leaving the laws open to inappropriate use by authorities such as monitoring citizens," Craveiro told AFP on the sidelines of the Fourth Meeting of the Internet Governance Forum in Egypt.
"Technicians need to communicate with lawyers to come up with more efficient legislation so that society doesn't end up paying the price for too broad a legislation," she said.
Craveiro was speaking at a session entitled Developing Comprehensive Cybercrime Legislation organised by the Council of Europe at the Red Sea meeting.
"Legal frameworks should take into acount the rights of users and the role of the private sector on the one hand, and security concerns on the other," the Council of Europe said in a statement. Kioskea
Gisele Da Silva Craveiro from the University of Sao Paolo in Brazil said the broad nature of cyberlegislation leaves it open to abuse by authorities.
"Definitions for cybercrimes can be so broad as to fit everything... leaving the laws open to inappropriate use by authorities such as monitoring citizens," Craveiro told AFP on the sidelines of the Fourth Meeting of the Internet Governance Forum in Egypt.
"Technicians need to communicate with lawyers to come up with more efficient legislation so that society doesn't end up paying the price for too broad a legislation," she said.
Craveiro was speaking at a session entitled Developing Comprehensive Cybercrime Legislation organised by the Council of Europe at the Red Sea meeting.
"Legal frameworks should take into acount the rights of users and the role of the private sector on the one hand, and security concerns on the other," the Council of Europe said in a statement. Kioskea
Tuesday, November 10, 2009
An FBI Cybercrime Agent's Tales From the Trenches
The stories that FBI Assistant Director of Cybersecurity Shawn Henry can tell are enough to keep any network security administrator up at night. The methods of criminal hackers are becoming disturbingly effective, he says, and changing attitudes on the nature of online privacy are giving rise to additional risks. On the bright side, he also sees a growing degree of cooperation among law enforcement groups.
Increase Customer Sales with VerticalResponse Email Marketing! Quickly and easily send email newsletters, coupons & sales announcements to your customers – no technical expertise needed. Sign up for your Free Trial today and send 100 emails on us!
The FBI official in charge of major cybercrime investigations told a international gathering of computer security experts last week that financial services companies have suffered massive thefts due to hackers.
Ecommerce Times
Increase Customer Sales with VerticalResponse Email Marketing! Quickly and easily send email newsletters, coupons & sales announcements to your customers – no technical expertise needed. Sign up for your Free Trial today and send 100 emails on us!
The FBI official in charge of major cybercrime investigations told a international gathering of computer security experts last week that financial services companies have suffered massive thefts due to hackers.
Ecommerce Times
Sunday, November 8, 2009
Small firms more susceptible to cyber crime
CHICAGO, Nov 8 — A couple years ago a crippling cyber attack on one of Nanette Lepore’s haute couture boutiques served as a wakeup call for the fashion retailer to get serious about its online security.
In 2007, Nanette’s Las Vegas store had its router hacked by a cyber criminal and confidential point-of-sale information was accessed, potentially impacting hundreds of the company’s well-heeled patrons. The sensitive data was then transferred to Italy, where it was used to create phony credit cards that were subsequently distributed in Spain.
After a meeting with FBI and local crime officials, the Caesars Palace store was shut down during crucial Saturday shopping hours, but the company gained a valuable lesson about protecting its data.
“If they can gain access to your network routers, you’re pretty much an open book,” said Jose Cruz, Nanette Lepore’s director of information technology, who has since developed a Fort Knox-like security protocol for the confidential information flowing through the company’s 10 boutiques and its New York headquarters. “The first thing I did was lock it all down.” Reuters
In 2007, Nanette’s Las Vegas store had its router hacked by a cyber criminal and confidential point-of-sale information was accessed, potentially impacting hundreds of the company’s well-heeled patrons. The sensitive data was then transferred to Italy, where it was used to create phony credit cards that were subsequently distributed in Spain.
After a meeting with FBI and local crime officials, the Caesars Palace store was shut down during crucial Saturday shopping hours, but the company gained a valuable lesson about protecting its data.
“If they can gain access to your network routers, you’re pretty much an open book,” said Jose Cruz, Nanette Lepore’s director of information technology, who has since developed a Fort Knox-like security protocol for the confidential information flowing through the company’s 10 boutiques and its New York headquarters. “The first thing I did was lock it all down.” Reuters
Wednesday, October 21, 2009
Coffins in the Mail Are a Trick of the Cybercrime Trade
There's never been a better time to get involved in cybercrime.
That's the tongue-in-cheek assessment of Uri Rivner, RSA's head of new technologies for identity protection and verification, who gave a presentation at the RSA security conference in London on Wednesday.
But there is truth in his quip -- the poor economy is driving people to find other work and it has become much easier for cybercriminals to recruit people, known as "mules," to carry out crucial duties for scams.
Seduced by promises of extremely high weekly pay while working only a few hours, people agree to do tasks such as reship goods or allow their bank accounts to receive funds for transfers elsewhere.
The problem is, the goods are stolen, and their addresses are being used as drops, allowing the cybercriminals the luxury of not receiving the stolen goods directly that have been bought with stolen credit card data. Mules are also duped into allowing money to be transferred into their own bank accounts and then ordered to transfer the money elsewhere, a type of money laundering.
PC World
Wednesday, October 7, 2009
Citing cybercrime, FBI director doesn't bank online
IDG News Service - The head of the U.S. Federal Bureau of Investigation has stopped banking online after nearly falling for a phishing attempt.
FBI Director Robert Mueller said he recently came "just a few clicks away from falling into a classic Internet phishing scam" after receiving an e-mail that appeared to be from his bank.
"It looked pretty legitimate," Mueller said Wednesday in a speech at San Francisco's Commonwealth Club. "They had mimicked the e-mails that the bank would ordinarily send out to its customers; they'd mimicked them very well."
In phishing scams, criminals send spam e-mails to their victims, hoping to trick them into entering sensitive information such as usernames and passwords at fake Web sites.
Though he stopped before handing over any sensitive information, the incident put an end to Mueller's online banking.
"After changing our passwords, I tried to pass the incident off to my wife ... as a teachable moment," he said. "To which she deftly replied, 'Well, it is not my teachable moment. However, it is our money. No more Internet banking for you."
Mueller said he considers online banking "very safe" but that "just in my household, we don't use it."
Phishing has evolved into a big problem, not just for banks, but for online retailers and even providers of consumer Web applications such as Facebook and Yahoo.
In June -- the latest month for which figures are available -- the Anti-Phishing Working Group counted nearly 50,000 active phishing Web sites, the second-highest number it has ever recorded.
Late last week, criminals posted tens of thousands of passwords belonging to Microsoft Live Hotmail, Gmail, and Yahoo accounts online. They are all thought to have been stolen via phishing.
Computer World
FBI Director Robert Mueller said he recently came "just a few clicks away from falling into a classic Internet phishing scam" after receiving an e-mail that appeared to be from his bank.
"It looked pretty legitimate," Mueller said Wednesday in a speech at San Francisco's Commonwealth Club. "They had mimicked the e-mails that the bank would ordinarily send out to its customers; they'd mimicked them very well."
In phishing scams, criminals send spam e-mails to their victims, hoping to trick them into entering sensitive information such as usernames and passwords at fake Web sites.
Though he stopped before handing over any sensitive information, the incident put an end to Mueller's online banking.
"After changing our passwords, I tried to pass the incident off to my wife ... as a teachable moment," he said. "To which she deftly replied, 'Well, it is not my teachable moment. However, it is our money. No more Internet banking for you."
Mueller said he considers online banking "very safe" but that "just in my household, we don't use it."
Phishing has evolved into a big problem, not just for banks, but for online retailers and even providers of consumer Web applications such as Facebook and Yahoo.
In June -- the latest month for which figures are available -- the Anti-Phishing Working Group counted nearly 50,000 active phishing Web sites, the second-highest number it has ever recorded.
Late last week, criminals posted tens of thousands of passwords belonging to Microsoft Live Hotmail, Gmail, and Yahoo accounts online. They are all thought to have been stolen via phishing.
Computer World
Thursday, October 1, 2009
At Least One Part of the Economy is Growing: Cybercrime
In case anyone thought it was getting easier to keep customer data safe, here are a few studies that will bring you back to reality.
The APWG (Anti-Phishing Working Group) released its latest Phishing Activity Trends Report and found that new records were being reached in a variety of areas, such as rogue anti-virus software, phishing websites and crimeware designed to target financial institutions' customers.
According to a release, the APWG H1, 2009 report found that the numbers of detected rogue anti-malware programs—fake security software that actually infects computers to animate assorted electronic crimes—grew 585 percent between January and the end of June 2009.
The number of unique phishing websites detected in June rose to 49,084, the highest since April, 2007's record of 55,643, and the second-highest recorded since APWG began reporting this measurement.
The number of hijacked brands also reached an all-time high of 310 in March and remained at an elevated level to the close of the half in June.
The APWG added a new metric to its Trends Report that measures proliferation of three categories of malevolent software: Crimeware (code designed to victimize financial institutions' customers); Data Stealing and Generic Trojans (designed to send information from the infected machine, control it, and open backdoors on it); and Other (commonly auto-replicating worms, dialers for telephone charge-back scams, etc.). This data was obtained from report contributor Websense.
This metric replaces counts of "Password-Stealing Malicious Code URLs" and "Password Stealing Malicious Code - Unique Applications" which, due to incongruent sources and counting methods became systematically unreliable.
According to Dan Hubbard, APWG Trends Report contributing analyst and Websense CTO, the growing complexity of these attacks is making it difficult for experts to distinguish between those attacks that are designed to steal banking credentials from customers.
"Due to evolution of attack sophistication, it is becoming increasingly difficult to separate and report on attacks that are specifically designed to steal customer banking information," Hubbard said in a statement. "Additionally, attacks that only look for credentials from popular social networking, web mail, and even gaming sites, can lead to attacks for banking theft and crimeware." Continue article (Finance Tech)
The APWG (Anti-Phishing Working Group) released its latest Phishing Activity Trends Report and found that new records were being reached in a variety of areas, such as rogue anti-virus software, phishing websites and crimeware designed to target financial institutions' customers.
According to a release, the APWG H1, 2009 report found that the numbers of detected rogue anti-malware programs—fake security software that actually infects computers to animate assorted electronic crimes—grew 585 percent between January and the end of June 2009.
The number of unique phishing websites detected in June rose to 49,084, the highest since April, 2007's record of 55,643, and the second-highest recorded since APWG began reporting this measurement.
The number of hijacked brands also reached an all-time high of 310 in March and remained at an elevated level to the close of the half in June.
The APWG added a new metric to its Trends Report that measures proliferation of three categories of malevolent software: Crimeware (code designed to victimize financial institutions' customers); Data Stealing and Generic Trojans (designed to send information from the infected machine, control it, and open backdoors on it); and Other (commonly auto-replicating worms, dialers for telephone charge-back scams, etc.). This data was obtained from report contributor Websense.
This metric replaces counts of "Password-Stealing Malicious Code URLs" and "Password Stealing Malicious Code - Unique Applications" which, due to incongruent sources and counting methods became systematically unreliable.
According to Dan Hubbard, APWG Trends Report contributing analyst and Websense CTO, the growing complexity of these attacks is making it difficult for experts to distinguish between those attacks that are designed to steal banking credentials from customers.
"Due to evolution of attack sophistication, it is becoming increasingly difficult to separate and report on attacks that are specifically designed to steal customer banking information," Hubbard said in a statement. "Additionally, attacks that only look for credentials from popular social networking, web mail, and even gaming sites, can lead to attacks for banking theft and crimeware." Continue article (Finance Tech)
Labels:
cyber crime,
cybercrime,
hijacked pcs,
malware. anti-malware
Monday, September 28, 2009
Outlook dim for international cooperation to fight cyber attacks
Protecting sensitive computer systems and networks from cyberattack requires international standards, but limited experience with Internet crime in developing countries and a reluctance from some nations to participate have stalled cooperation, said a panel of security experts on Monday.
"It's one grid, one global network, and we're all stuck in the same boat," said James Lewis, director of the technology and public policy program at the Center for Strategic and International Studies. "We need to establish some rules."
President Obama's cybersecurity plan, released in May, stated that "the United States needs to develop a strategy . . . to shape the international environment and bring like-minded nations together on a host of issues, including acceptable norms regarding territorial jurisdiction, sovereign responsibility and use of force." The plan also included among its 10 near-term priorities the development of a framework for international cybersecurity policy.
The obstacle, however, is convincing countries to cooperate with the international effort, including the prosecution of cybercriminals.
NextGov
"It's one grid, one global network, and we're all stuck in the same boat," said James Lewis, director of the technology and public policy program at the Center for Strategic and International Studies. "We need to establish some rules."
President Obama's cybersecurity plan, released in May, stated that "the United States needs to develop a strategy . . . to shape the international environment and bring like-minded nations together on a host of issues, including acceptable norms regarding territorial jurisdiction, sovereign responsibility and use of force." The plan also included among its 10 near-term priorities the development of a framework for international cybersecurity policy.
The obstacle, however, is convincing countries to cooperate with the international effort, including the prosecution of cybercriminals.
NextGov
Labels:
cyber attacks,
cyber crime,
obama cybersecurity plan
Sunday, September 27, 2009
Cyber-crime: Something’s Got to be Done, But By Whom?
When one considers some of the hotly debated issues of this Obama era, they often boil down to a single, overriding question: How far should the government go in regulating things such as health care, privacy, free speech, etc.? In other words, where does personal responsibility end and government responsibility begin?
This question was particularly brought to my mind by a recent Associated Press article, which noted that cyber criminals are increasingly targeting small and medium-sized businesses. These companies don't have the same resources as larger ones, which continually update their computer security and have more sophisticated systems, according to an official of the U.S. Secret Service's office of investigations.
According to AP, organized cyber groups based abroad are waging many of the attacks. They are stealing not only credit card numbers, but also personal information—including Social Security numbers—of the cardholders.
The article adds that lawmakers working on cyber security legislation are pressing for the Obama administration to do more to prevent such attacks. But just what do these people want the government to do? If a smaller company—say a Tier III insurer or and independent agency—doesn’t spend money on basic protections, does that mean the taxpayer has to step in and buy a security software suite or firewall device for the company or agency?
The very idea is ridiculous. In this Internet age, virtually no one is unaware of the basic need to protect systems and data. In the insurance industry in particular, where customer data is our very lifeblood, it is sheer lunacy to leave such information and systems vulnerable to attack. But more importantly, whose responsibility is it to protect customer data that resides on company systems? The answer—unless you are GM or Chrysler—is that the buck stops with the company. Believe it or not, Big Brother is not always watching us, and the safety of business systems would likely not be his No. 1 priority if he were doing so.
Are we seriously suggesting that the federal government should take responsibility for the security of business data and systems? Remember, this is the same federal government whose own systems have been repeatedly hacked by foreign governments and by technologically gifted slackers who seem to have nothing more constructive to contribute to society. This is also the same administration that, despite much bombast, has not appointed a cyber-security czar.
Insurance Networking
Ara C. Trembly (www.aratremblytechnology.com) is the founder of Ara Trembly, The Tech Consultant and a longtime observer of technology in insurance and financial services. He can be reached at ara@aratremblytechnology.com.
Subscribe to:
Posts (Atom)









