Password creation policies are the enemy of secure... » Commenting on reports that a security developer has concluded that password-creation policies are th... Thousands of Young Adventurers kept safe with M2M ... » Thousands of teenagers taking part in the annual two-day Ten Tors Challenge across Dartmoor in Devon... avast! Free Antivirus for Mac tops CNET’s download... » PRAGUE, Czech Republic: Three days after its release avast! Free Antivirus for Mac shot to first pos... USB-Tischmikrofone von Imtradex gewährleisten schn... » TM2-LS und TM3 verbinden innovative Technik mit einfacher Handhabung Dreieich: Schnelle und einfach... Opengear wins Information Technology Industry’s 20... » Opengear ACM5504-5-G-I Remote Infrastructure Management Gateway Honored at Interop Interop, Las Veg... ISACA Speaker urges IT candidates to shift career ... » In-depth discussion to be held at INSIGHTS 2012 London, UK: Recruiting in the technology sector is ... Venafi hails FBI’s hotel-network security warning ... » London: “Everyone with an Internet connection has a stake in understanding the critical links in the... Is loaphobia causing workers to fear losing their ... » 19% missed a critical deadline because they couldn’t access the right applications, 14% lost a job a... Whoopee! £38 billion blackhole in Defence budget e... » Vigilance can report that the MoD’s budget deficit has been wiped out for the first time in a genera... Media Alert: DDoS tool (LOIC) downloads increasing... » Imperva's Application Defense Centre has been tracking the Anonymous DDoS tool, LOIC, and the number...

Advertise with Vigilance

Got News?

Got news for Vigilance?

Have you got news/articles for us? We welcome news stories and articles from security experts, intelligence analysts, industry players, security correspondents in the main stream media and our numerous readers across the globe.

READ MORE

Subscribe to our Newsletter

Information Security Header

Below is a media alert by Amit Klein, Trusteer's CTO concerning development discovered by Trusteer in some new Ice IX configurations- a modified variant of the ZeuS financial malware platform that is targeting online banking customers in the UK and US.

Malware Redirects Bank Phone Calls to Attackers

Trusteer have discovered a concerning development in some new Ice IX configurations that are targeting online banking customers in the UK and US. Ice IX is a modified variant of the ZeuS financial malware platform.

In addition to stealing bank account data, these Ice IX configurations are capturing information on telephone accounts belonging to the victims. This allows attackers to divert calls from the bank intended for their customer to attacker controlled phone numbers. I believe the fraudsters are executing fraudulent transactions using the stolen credentials and redirecting the bank’s post-transaction verification phone calls to professional criminal caller services (discussed in a previous Trusteer blog) that approve the transactions.

In one attack captured by Trusteer researchers, at login the malware steals the victim’s user id and password, memorable information/secret question answer, date of birth and account balance.

Next, the victim is asked to update their phone numbers of record (home, mobile and work) and select the name of their service provider from a drop-down list. In this particular attack, the three most popular phone service providers in the UK are presented: British Telecommunications, TalkTalk and Sky. Here’s an example of the web injection the user sees in their browser:

To enable the attacker to modify the victim’s phone service settings, the victim is then asked by the malware to submit their telephone account number. This is very private data typically only known to the phone subscriber and the phone company. It is used by the phone company to verify the identity of the subscriber and authorize sensitive account modifications such as call forwarding. The fraudsters justify this request by stating this information is required as a part of verification process caused by "a malfunction of the bank’s anti-fraud system with its landline phone service provider".

Here are the web inject messages presented to BT, TalkTalk and Sky users:


Amit Klein, CTO of Trusteer said, “As Trusteer discussed in a recent blog, fraudsters are increasingly turning to these post-transaction attack methods to hide fraudulent activity from the victim and block email and phone communication from the bank. This allows attackers to circumvent security mechanisms that look for anomalies once transactions have already been executed by the user.”

Deterministic detection security mechanisms like Trusteer Rapport, which search for specific malware Crime Logic footprints before transactions are submitted and allow the online banking application to stop fraud by changing business flows (block money transfers, decline add payee, limit amounts, etc.), are not vulnerable to post transaction attacks

Add comment


Security code
Refresh