Thursday, April 17, 2008
Symantec releases Internet Threat Security Report
The report confirms that hacker tool kits are increasingly making it easier for less sophisticated types to effective commit technical crimes. Symantec also believes that these tool kits are being professionally developed, which supports the deduction that the underground community is maturing and consolidating.
Perhaps the availability of tool kits is the reason that a 559 percent increase in phishing websites has been noted?
The report also shows that the bad guys are going after "trusted" sites, such as social networking sites.
The underground economy in stolen financial details is also on the increase. These details, which are sold in Internet forums are getting cheaper. With all the phishing going on coupled with a record amount of data breaches an over abundant supply of stolen information is likely the reason for this. The report found a wide variety of pricing on payment card numbers, ranging from .40 cents to $20 per card.
The easy availability of encoders and other portable payment card technology makes it "too easy" to counterfeit the numbers into realistic looking plastic. In addition to this, there is a thriving market in counterfeit documents, which provides a wide-array of realistic counterfeit identification to vet the counterfeit financial instruments.
Besides identities and payment card details, stolen bank accounts are becoming increasingly available. Symantec attributes the increase in bank account information to a mirror increase in banking trojans over the second half of 2007.
Besides being used to clean out an account, bank account details are useful to criminals when they commit check fraud. Anyone, who follows scams on the Internet, knows that counterfeit checks are being delivered to unsuspecting mules to cash in a variety of advance fee (419) type scams. Please note there are organized gangs, who move from area to area committing check fraud using mules, who know exactly what they are doing, also.
Recently, an International task force monitored the mail and discovered large amounts of counterfeit checks being shipped throughout North America and the European Union.
All in all this report is a very interesting read. If you are a more visual type, Symantec also did a very nice flash presentation on this, which can be seen on the page linked to in the previous sentence.
Thursday, February 28, 2008
Finjan discovers criminal database with 8700 account credentials to trusted domains!
It should be noted that government domains have been allegedly compromised, also.
From the Finjan press release:
Finjan Inc., a leader in secure web gateway products, today announced it has uncovered a database containing more than 8,700 harvested FTP account credentials, including username, password and server address - in the hands of hackers. These stolen credentials enable criminals to compromise servers and automatically inject crimeware to infect users visiting them. Among those stolen accounts are those of Fortune-level global companies in a wide range of industries including manufacturing, telecom, media, online retail, IT, as well as government agencies. The stolen FTP accounts include some of the world’s top 100 domains as ranked by Alexa.com.
Dark Reading Kelly (Jackson Higgins) went more into depth on the risks associated with this new discovery:
The so-called meoryprof.info (Me-or-you-Profit) site is selling username, password, and server addresses of these FTP servers as well as the NeoSploit Version 2 crimeware package, which basically lets the bad guys who buy it instantly infect these sites with malicious code -- with the goal of stealing valuable and confidential data from them as well as any visitors to the sites. It also “qualifies” the stolen accounts so that buyers either can then set a price to resell the compromised FTP credentials to other cybercriminals, or determine which are the more potentially lucrative sites to hack.
“With a click of a button they say ‘I want to infect his FTP server’ with the crimeware,” says Ben-Itzhak. Finjan did not test all of the sites to see if they had been infected yet or not.
From a more social perspective, this continues the scary trend of crimeware for sale, which enables not very technical criminals to commit fairly technical crimes at will.
Besides the fact that (in theory at least) sensitive information can be stolen from some of these sites, a visitor can be compromised when visiting a "trusted site."
Besides the risk of sensitive information being compromised, compromised sites, once publicized might face another problem a.k.a. unfavorable public exposure. This could lead to a loss of trust in their brand, and as seen recently, potential litigation.
This doesn't even take into consideration all the other assorted costs of recovering from a large scale data compromise that becomes public knowledge.
Finjan is inviting the corporate world to make inquiries, whether or not, their particular site is at risk. I'll provide the link to do so, here.
They are also providing more information on this latest crimeware kit on their "Malicious Page of the Month."
Dark Reading story, which seems to be a good information source on this story, here.
Saturday, September 08, 2007
SIRAS PI - tracking theft to the source

Graphic demonstration of anti-theft technology courtesy of SIRAS.com.
Criminals, who steal goods, whether with bogus financial instruments, or by more physical means might be in for a little surprise if the merchandise is protected by SIRAS PI.
Last week, SIRAS made this announcement in a press release:
SIRAS.com, the pioneer in Point-Of-Sale Electronic Product Registration used by leading manufacturers and retailers, has announced the nationwide launch of SIRAS P.I., a groundbreaking initiative to aid law enforcement officials in determining whether products they recover are, in fact, stolen, and if so, from where. Piloted by the Mesa, Arizona Police Department, SIRAS’s P.I. (Product Information) Database has already proven to be effective in helping law enforcement officials identify stolen items, report suspicious items, and apprehend and convict thieves. The database will be available, free of charge, to police and law enforcement agencies nationwide.
The way SIRAS works is simple, but effective. It tracks a product by recording the UPC (Universal Product Code) and the product serial number. SIRAS has the capability to determine where merchandise was stolen, whether from a merchant, manufacturer, or individual.
Earlier this year, SIRAS did some testing that revealed a substantial reduction in TV and MP3 player losses on products, where their technology was being used.
If deployed properly at the merchant level -- it could also determine how an item was purchased, and whether or not -- the method of payment used was legitimate. In theory, a merchant could also use the technology to impact credit card chargeback and fraud check losses.
I say "deployed properly" and "in theory" because the information to accomplish this (sales data) belongs to the company using SIRAS technology. Because of this, the capability to track sales information would have to be implemented inside the company. At most larger companies, this information is already tracked and analyzed to prevent and detect dishonest activity.
For years, most high-theft (shrink) merchandise has been secured so a thief can't merely pick it up from a shelf. When high-theft merchandise that was secured is stolen, it's normally because of one of two reasons. It was purchased with a bogus financial instrument, or an insider was involved in the theft.
Other reasons for secured merchandise being stolen might be a theft, directly from the manufacturer, or a theft during the shipping (transport) process. In these instances, if the merchandise was registered at the manufacturer, SIRAS can identify the point of compromise, also.
Technology has made it a lot easier for criminals to obtain and use fraudulent forms of payment. Information being compromised (data breaches) and anonymous places to communicate like Internet chat rooms, have given a lot of common criminals access to bogus financial instruments.
Along with the increased availability of fraudulent forms of payment, obtaining counterfeit identification documents has become fairly easy, and the identity used on them normally belongs to someone else. This has made it easy for a lot of retail criminals to operate as someone else.
Because of these new trends, current systems that record personal information to prevent fraud are becoming less effective than they use to be. I often wonder (no one probably really knows) how much of the information contained in them is incorrect.
In the recent data breach at TJX, one of the systems compromised was their refund database. Stories have circulated recently about the wrong people being pegged as frequent refunders, or bad check writers after their identities were stolen.
Neither one of these situations fosters good will, or trust with customers. Besides that, data breaches are becoming costly. The last I heard TJX has spent approximately $256 million dealing with the breach. With pending litigation, the cost is liable to keep going up.
With SIRAS, using personal information isn't necessary to determine, whether or not, a return is legitimate. SIRAS already has proven to be highly effective in reducing refund fraud without asking for one item of personal information.
An example of how some of the TJX data was used in a retail theft scenario can be seen, here.
Given that criminals that steal merchandise want to turn it into money, two methods are normally used. They either refund it somewhere, or fence it. Auction sites provide an easy and when combined with account-takeover activity (anonymous) venue for criminals to fence merchandise.
In the auction world, seller accounts are taken over all the time. This normally occurs when seller accounts are compromised by a phenomenon known as phishing. Phishing occurs when a person is tricked into giving up their access information after receiving a spam e-mail.
Compromised seller accounts are sold on the Internet the same way financial information is, and there is a trend in DIY (do-it-yourself) phishing kits being sold that enable non-technical criminals to get into the game.
eBay and PayPal are two of the most heavily phished brands. Once these accounts are compromised (taken over), they are used by criminals to fence merchandise and launder the monetary proceeds of their illicit sales.
Another growing trend related to phishing is when malware, also sometimes known as crimeware is used to steal information. The difference here is information is stolen from systems automatically (normally by keylogging software) and social engineering (trickery) is no longer necessary to get people to give up information.
Malware is often picked up by a computer system by clicking on a spam e-mail link, or by visiting a website designed to inject the software on a system. PC World recently did one of the many stories floating around about malware being sold on the Internet in the form of DIY kits.
In the story they wrote:
The global market for criminal malware now operates like a supermarket, complete with special offers and volume discounts, a security company has discovered.
Here again, this capability enables not very technically inclined criminals to get into the game. This has become a growing problem and I expect it to get worse before it gets better.
With the availability of all this personal and financial information, being sold on an economy of scale, current fraud protection systems are routinely being compromised by a lot of criminals.
There is an old saying in the investigations world, which is if you want to solve a crime, the easiest way is to follow the money.
SIRAS takes this one step further by tracking both the merchandise and can track the money ( if programmed to do so by the user). When you do this, the odds are far greater that the true culprit will be identified. They are normally associated with either the money, and or the merchandise.
Since the technology records both physical and UPC information, the database can determine exactly where the merchandise was compromised (stolen). Given that many merchants use digital video systems -- which are capable of storing video footage for a long time, it's also possible to obtain video evidence of the original transaction -- when sales information has been programmed to tie into the technology.
SIRAS has been used by select manufacturers and merchants for several years now -- however a new initiative, SIRAS PI, which was tested with Mesa PD -- makes the database available to law enforcement agencies free of charge.
Law enforcement can access the database either via the Internet, or by telephone. They can also add items to the database when they are reported stolen. If someone later tries to refund the merchandise at a participating retailer, the transaction can be automatically flagged.
Although a lot of fencing now occurs on the Internet, the technology is equally as effective in investigating more traditional property crimes, also. The bottom line is once merchandise is discovered, it can be tracked by SIRAS, if the item has been registered.
Recently, Chris Hansen (MSNBC), did a story about iPod theft. When Apple was approached about tracking the merchandise using Apple's registration database, they decided not to cooperate with MSNBC.
Undaunted by this, MSNBC purchased a bunch of iPods and engineered the registration disc to send them the information when the iPod was registered. They then left the iPods (new in the box) unattended, let them get stolen and tracked them to the crooks once the iPod was registered.
Chris Hansen made an excellent point on how databases can track stolen merchandise -- but in this instance, brand new iPods had to be left in public places to be stolen -- then registered to make the point.
If Apple used SIRAS technology to protect their merchandise -- it would have already been traceable, even if it was stolen from an individual -- who didn't provide the thief with the registration disc. It also would eliminate privacy concerns, which might be why Apple didn't want to cooperate with the MSNBC investigation?
When registering any product, a lot of personal information is normally asked for.
In any event, most criminals of the smarter variety aren't going to provide their personal information in the registration process. Most of them shy away from doing things, which might get them caught.
It would be interesting to have MSNBC, or another investigative news source do the same story with merchandise protected by SIRAS. The story might expose more than people, who stole because of an almost "too good to be true" opportunity was provided to them.
MSNBC iJacking story, here.
This brings up another potential benefit to this technology. Expensive portable electronics and other expensive toys like mountain bikes are stolen from the people who buy them (customers) all the time. Using SIRAS technology might even be a selling point that instills customer trust in the product they are purchasing.
This technology has prevention/investigation applications for corporations, law enforcement agencies and individuals, alike. It also doesn't require using people's personal information, which isn't as effective as it used to be, and is becoming more unpopular all the time.
In my opinion, this technology has the ability to make it a lot harder to get away with stealing merchandise and converting it into money.
Of course, the more it is used, the more effective it will become. Databases have a tendency to do this, or become more useful as they contain more information.
There are a lot of anti-theft/fraud technologies that claim to prevent theft/fraud. Very few of them also claim to be able to go after and hold the criminals committing the fraud/theft personally accountable.
The last I heard, most criminals still fear getting caught!
If you would like more information on the organized trade in counterfeit identification documents, the story of Suad Leija can be seen, here.
Suad's story has been covered extensively in the media, including by Lou Dobbs. Currently, she is writing a book and I keep in touch with her occasionally.
More information about bogus financial instruments can be seen, here and here.
A chronology of data breaches is compiled by the Privacy Rights Clearinghouse, here.
The best source on phishing is the Anti-Phishing Working Group and if you are interested in learning even more about phishing and want to see some totally fake banking sites, Artists Against 419 is another good place to visit.
Last, but not least, if you are interested in learning more about SIRAS PI, you can do so by visiting their site, here.
Tuesday, June 05, 2007
Spear phishermen target executives to steal company information
The phishermen normally send out a lot of bait (spam) in the hopes of hooking a few phish.
Shamus writes:
Over the last week and a half, spam messages purported to be from the Internal Revenue Service and the Better Business Bureau have been specifically targeting senior-level corporate executives with phishing scams.Spear phishing is simply a more focused form of phishing, which uses more personal touches, such as a person's real name, and or title.
Experts say these targeted phishing attacks, sometimes called "spear phishing," are nothing new, but they illustrate that spammers are getting more adept at targeting sophisticated email users who have access to the most sensitive data within their companies.
With all the information plastered over the Internet, or available for sale; it isn't hard for phishermen to get what they need (personal information) to go spear phishing.
Many private companies and government organizations recognize the danger phishing poses in the workplace. To counter this, and raise awareness; they are phishing their own employees.
Recently, I did a post about this, which revealed more employees fall for this, than many would like to admit:
Technology alone isn't going to stop phishermen and other cyber ghouls on the Internet
There seems to be more and more phishing out there, which might be inspired by DIY (do it yourself) kits being sold over the Internet. DIY kits make it easy for not very sophisticated criminals to become expert phishermen.
The only good news about phishing is that with a little awareness, most people can spot this activity, because the phishing ploy doesn't make much sense, or is too good to be true.
CIO News story, here.
BBB Alert, here.
IRS Alert, here.
Sunday, May 20, 2007
Technology alone isn't going to stop phishermen and other cyber ghouls on the Internet
It didn’t surprise me that many of the phish took the bait, pretty easily. It would just mean that the federal employees, who were phished are no different from the general population on the Internet.
After all, there wouldn’t be so much phishing, if it didn’t work.
Apparently, the practice is catching on and Amy Joyce of the Washington Post did an interesting article about why the idea might be a good one.
In the article, James MacDougall (South Carolina’s computer security guru) as saying:
You can spend all the money on the technology you want, MacDougall said. But if the end users are doing dangerous behavior, there is almost no cure for that.
Mr. MacDougall has hit an important point right on the head and phishing tends to set new records, every time the Anti Phishing Working Group issues their monthly report. Their most recent report (April) indicates that not only did the number of phishing sites set a new record, but their numbers more than doubled over the previous month (March).
Spam filters designed to stop phishy e-mails seem to be under major attack, and haven't been very effective in the recent past, either.
Maybe, we are spending too much money on technology to solve the problem rather than using some good old fashioned common sense?
One of the reasons, technology tends to be defeated, or used by criminals – is that it is too easily compromised by human beings. Most financial scams rely on the greed factor, or getting people to fall for something that's too good to be true.
It doesn’t take a genius to buy DIY (do it yourself) crime kits, which are readily available over the Internet, and commit what some might consider, sophisticated criminal activity.
Relying on technology to protect us without human oversight is a big mistake, and this holds true, for more than financial crimes.
Government and private systems are attacked all the time for their information.
Technology is a wonderful tool and makes things easier, but it has limitations. Instead of throwing all of our resources into technology, which seems to have a limited life span, maybe we need to focus more on the human factors that put us at risk, daily.
Thought provoking story by Amy Joyce, here.
Monday, May 07, 2007
Is Target's payment card and new refund procedure stopping retail criminal activity?
So far as the new refund policy, Target's response is that this will affect a very small amount of its customers. Chris Serres, Star Tribune, Minneapolis - St. Paul gives Target's rationale for this:
Law enforcement officials have a different take on this:Target officials said the new limits affect fewer than 5 percent of its customers. Shoppers who have bought products with credit cards, debit cards or checks can still return them without receipts, without having to worry about the new limits.
"While we expect the changes to ... impact a very small number of guests, our goal is to minimize losses regardless of amount," said Amy von Walter, a Target spokeswoman.
Sophisticated fraudsters are becoming the norm with data breaches, carder forums, and do it yourself (DIY) crime kits being marketed via the Internet.Target's practice of not checking the IDs of credit card holders has made it a target for more sophisticated fraudsters, said Brandon Deshler, an officer with the Edina Police Department and a detective with the Minnesota Financial Crimes Task Force, a state law enforcement agency. "There is a real inconsistency here," he said.
I keep reading about how identity theft is tied into methamphetamine use, but in reality, it might also be tied into heroin use, or any other narcotic that people get addicted to. Addicts often turn to retail crime to support their habits, also.
Before the Internet made sophisticated fraud pretty easy to accomplish, addicts did a lot of shoplifting (boosting) to support their habits.
As time went on, retailers got smarter. They started locking up high value (shrink) merchandise and tightened up their return policies. To get past this, many retail criminals use fraudulent payment devices, which are pretty easy to obtain.
Organized criminals now make their "cut" selling the information and devices to less sophisticated crooks, who do all the dirty work for them. Deals are made on the Internet with a click of a mouse, and these devices are (normally) shipped from foreign sources, where it is hard to identify the criminals behind it.
Fraudulent devices are ordered in chat rooms, paid for by wire transfer or PayPal, and shipped to these (questionably) sophisticated criminals UPS, or Fedex, worldwide. Sometimes, they are shipped in bulk to one location and then redistributed. This is another method used to make tracking these devices to their original source, difficult.
Because of the growing availability, retail criminals are using fraudulent payment devices to obtain and then refund merchandise.
If customers using credit cards, debit cards and checks are still allowed to return them without receipts, I'm guessing a lot of refund fraud will still occur.
I wondered how customers, using payment devices (checks, credit cards, debit cards) could get a refund without a receipt? Just to make sure, I called my local Target and told them I lost my receipt from a credit card purchase. I was told to bring my credit card in and they could look up the information.
In light of the many recent data breaches, such as TJX -- where at least 45 million customers were compromised -- this thought scared me. Even if their systems are completely safe (not sure if any really are), does this mean that a dishonest employee could access my information? Employee dishonesty has long been (and still is) a major problem at most businesses.
The best thought out security can be beat by one person with access to it!
One of the systems compromised at TJX was their refund authorization system. Not allowing easy access, or even maintaining personal and financial information is the recommended way to prevent data theft.
Besides that, I often wonder how accurate the data is in some of these refund systems. These days, crooks use a lot of other people's information.
Since Target relies on electronic authorization systems (they don't even require their staff to check ID) on credit/debit card transactions, the law enforcement official quoted above might have a very valid concern.
But this isn't the only time, I read about this concern in the past week.
An article came out from Washington about an enraged identity theft victim, who after realizing no one was doing anything with her case, decided to beat the pavement (investigate), herself. Working with a reporter, she did her own check of retailers and here is what happened at Target (as reported on KOMOTV.com):
We did the same thing at Target. This time, we included wine in our purchase thinking some stores require an ID check when buying alcohol. At no point during our checkout did the Target clerk even ask to see the credit card. The clerk never asked for an identification check.
In a statement, Target says it does not require its clerks to handle or inspected credit cards.
Instead the store relies on an electronic authorization system where the customer swipes their own credit card through a reader."Electronic authorization is faster and more accurate than relying on visual inspection of verification of written signatures," says Brie Heath of Target.
Even with these systems, where a customer swipes their own card, a lot of retailers require that the clerk check identification AND inspect the card on signature transactions. In fact, a lot of pos (point-of-sale) systems prompt the customer and the clerk to do so.
Counterfeiting payment cards has become so easy to do that it's now done in garages with hardware that can (unfortunately) be bought over the Internet. Granted, identification can also being counterfeited, but at least visual inspection is going to making it a little harder to commit payment (debit/credit) card fraud.
The truth is that electronic verification systems read data, and in the case of debit and credit card data, it's being transferred (counterfeited) all the time.
Many might ask why Target would rely on an electronic system with so much fraud going on out there? One reason might be that when a card is "swiped" (electronically authorized), it is pretty hard for the bank to charge it back to Target.
When this happens, I'm guessing that Target isn't the one taking the loss, the bank does.
Chargebacks are becoming a huge issue, and many merchants (especially e-commerce merchants) are saying they are unfair to them, also. These merchants claim the rules favor the banks, who are passing off the costs of fraud to them. With the recent TJX data breach, and the realization of how expensive information theft has become, we can expect to see more controversy on this issue.
It's sad that businesses seem to be spending more time going after each other than the criminals behind the activity (my emphasis).
We also need to consider the considerable grief, victims go through in this process. Victims can be held liable for losses, have their credit ruined, and are even charged with crimes they didn't commit. Some of these victims are undoubtedly past, present, or future customers.
It's pretty easy for me to understand law enforcement officials and identity theft victims might be a little frustrated with Target's policies.
There is no doubt that the amount of refund and payment device fraud is growing. Businesses do have the right to protect themselves, but passing the financial loss to another business, and ultimately (all of us) does little to stop the problem. In fact, it might be one of the reasons this type of fraud is growing.
It would be unfair to single out Target on these issues. Other retailers need to be looking at them, also. Retailers are sold expensive security technology and too often (my emphasis) find that someone has figured out a way to exploit it.
Systems get defeated by human beings all the time. The best defense against this are other human beings. Removing human interface from the equation makes it easier to commit fraud (my emphasis).
Star Tribune article, here.
KOMOTV.com article about the identity theft victim doing her own investigation, here.
Saturday, November 18, 2006
Why Do We Keep Blaming Identity Theft Victims?
At first, I thought "here we go again," but in reality -- there are probably thousands of laptops that have disappeared in the private sector that were never made a public record via the "Freedom of Information Act."
In fact - in a lot of the data breaches observed - the breached seem to disclose as little as possible. I wonder if we know about every data-breach that might have occurred?
Articles about missing laptops compromising "millions" make good stories, but in reality, laptops are a desirable item and get stolen all the time. It's entirely possible they are bought and sold on the black market and even used by criminals, who are clueless of their "information value."
I predict sometime in the near future, we'll see a story on information was compromised by the theft of a smart phone. They're pretty easy to steal and (desirable), also.
On the other hand - with chat forums selling personal information for a few dollars a pop - the amount of compromised information out there is potentially huge.
Recently, we saw stories where personal information was being harvested off hard-drives that were thrown-away, or given to charity. How many hard-drives have been discarded without removing the information on them?
Again - with the amount of personal information being stolen and used in financial crimes - who knows? Some "expert" will argue that none of it has been used and the criminals using it are unlikely to comment.
No matter where it comes from, the astronomical increase in identity theft, clearly indicates that a lot of information is being compromised - whether stolen from a laptop, garbage can, or via malicious software, sometimes referred to as crimeware.
I had to chuckle recently when some "security experts" observed that in most identity theft cases, the information compromised came out of trash cans. Whether they are right, or wrong - the information sent in mass mailings starts in a database - sold for a profit and printed on a computer.
The only difference is the method of mail being used. Trust me, the Postal Inspection Service investigates a tremendous amount of fraud that is sent via snail mail and mail fraud is nothing new.
Yes - according to the experts - we are to blame and need to take action to ensure criminals don't compromise the sensitive information being sent to us in mass mailings. Is anyone paying us for our time to rectify a problem, we didn't create? Has anyone ever considered that maybe we shouldn't be mailing this type of information and then making it too easy to obtain one financial instrument, or another?
We see technology fixes, which are highly publicized, but seem to have short lifetimes after "saavy" criminals defeat them. An example of this is the "chip and pin" technology - which seemed to be compromised in no time at all on older ATM machines.
There are still a lot of older ATM machines to be used.
I've also seen "experts" blame people for not keeping their virus protection up-to-date, or falling for social engineering schemes. Are they to blame for e-commerce sites that are easily faked and complete "do it yourself" scamming kits routinely available on the Internet?
An entire security industry has grown up around this problem and if you want protection - which doesn't always work - you need to line someone's pockets. In fact - in many instances - you not only have to line their pockets once, but you also have to pay for all the countermeasures that are developed when their measures are defeated.
Businesses love income streams.
Then there are the faux providers of protection, which can lead to more information being sifted from your computer if you happen to download their "fixes." It's very difficult for most consumers to determine - who is reputable and who is not - when their ads are right next to each other on the Internet.
Sadly enough - one of the solutions has been to offer "identity theft insurance," which means that people are being asked to finance their own protection. A lot of this is being sold by the same people, who are buying and selling all the information that caused the problem in the first place.
We need to address to the real issue, which is there is too much information out there that is "poorly protected" and easily accessed for "dubious purposes."
Please note that I'm not advocating that people don't need identity theft protection, or to protect their systems. Virus protection, firewalls and identity theft protection are probably good things to have in the current enviroment we are dealing with.
And I'm not saying all the "experts" are wrong. Trust me, a lot of them are hard working, thoughtful and dedicated people trying to make a difference. The problem is that money can buy a lot of experts and those using and abusing people's personal information have plenty to spend.
We need to stop believing that technology can cure the problem and realize we are dealing with a social issue. The bottom line is that a lot of sensitive personal information is being poorly protected and too many people are being victimized by the use of it.
Since so much money is being made by making "sensitive information" too easy to access, the people making a lot of money are resistant to change. Until we make it less profitable for them to continue "enabling" the problem, the problem isn't going to disappear and is likely to grow.
If the people enabling the problem are "resistant to change," perhaps the answer is to create laws to protect the innocent and make it a little harder for the guilty to do business as usual!
Blaming victims for something they didn't cause is getting a little old!
Wednesday, September 06, 2006
Do It Yourself Crime Kits Victimize the Masses
Phishing is a leading cause of identity theft, which impacts millions of people a year.
Dinah Greek, Computeract!ve reports:
This was the warning from the Anti Phishing Working Group (APWG) , which said the kits allow non-technical criminals to start up their own online criminal empires.
All the information they need to set up phishing emails or websites infected with malware, such as Trojans, viruses and worms, is contained in the kits bought and sold online.
Full story, here.
Do it yourself (crimeware) kits aren't entirely new and have been reported before, here.
We keep hearing about the record number of phishing attempts being recorded. Unless some of these people start getting caught - we are likely to see the number continue to grow!
And the criminal "do it yourself industry" doesn't limit itself to phishing. Kits on how to scam on auction sites are also being sold (previous post), here.
Sunday, May 07, 2006
Internet Crimes are On the Rise and Deadlier than Ever
Here is their summary:
This report confirms the new malware dynamic based on generating financial returns. Spyware, Trojans, bots and dialers were the most frequently detected types of malware between January and March 2006. Trojans accounted for 47 percent of new malware examples during the first quarter of 2006.
Seventy percent of malware detected during the first quarter of 2006 was related to cyber crime and more specifically, to generating financial returns. This is one of the conclusions of the newly published PandaLabs report, which offers a global vision of malware activity over the first three months of the year. Similarly, the report offers a day by day analysis of the most important events in this area. This report can be downloaded, free of charge, here.
Since this statistic interested me, I jumped over to the Anti-Phishing Working Group's page to see what they had to say. Please note that Panda, along with Websense and MarkMonitor share information with the APWG. They confirmed Panda's report that crime on the Internet seems to be at an all time high.
Here is a tickler from their report:
The total number of unique phishing reports submitted to APWG in March 2006 was 18,480, the most reports ever recorded. This is a count of unique phishing email reports. March 2006 continues the trend of more phishing attacks and more phishing sites. The IRS phishing attack doubled in volume in March as compared to February (in the USA, the tax filing deadline was April 17 in 2006, as the usual April 15 deadline fell on a weekend this year.)
Link, here.
Two of the most concerning forms of malware being used are Keyloggers and Redirectors. Keyloggers are a form of spyware, which record all the strokes on a computer and transmits them to back to the person (criminal), who installed the malware. They are normally used to steal financial information, used in identity theft schemes.
Sadly enough, Keyloggers are legal and easily bought anywhere, including the Internet. They allegedly have legitimate uses like spying on other people?
Perhaps, the FTC should go after some of these vendors like they recently did with the Private Investigators selling telephone records?
Redirectors are a trojan, which once installed on a computer, redirect the user to malicious sites, where their financial information is stolen. The sites are also known to download more malware (crimeware) on systems. Redirectors are extremely dangerous because there is little indication you are being hijacked.
The Anti-Phishing Working Group has some excellent educational information on this subject, including what to do if you become a statistic:
How to Avoid Phishing Scams
What To Do If You've Given Out Your Personal Financial Information
Too many people (who know what to look for) ignore and delete phishing attempts. There are a lot of places you can report activity and make an impact. In most cases, it only takes a minute or two to do so.
You can report phishing activity to the APWG, here. Activity can also be reported to PIRT, which is a joint venture by Sunbelt Software and CastleCops.
Another resource to report activity is the Internet Crime Complaint Center, which is associated with the FBI. You can report it a lot of places, but it is important to report it. If everyone took the time to report one phishy email a day, it would probably have a significant impact.
By reporting the activity that we see and taking advantage of the mostly volunteer efforts to fight it, we might make the Internet a safe place for everyone again. As access becomes cheaper and more widespread, the number of potential victims is growing at a record rate.
Continuing to ignore all those "Phishy" e-mails will only encourage the Phishermen to move forward with greater frequency. Additionally, the attacks are becoming more sophisticated and "how to kits" are being sold on how to do these dirty deeds. This will undoubtedly bring more and more Phishermen to the (already) murky waters of the Internet.
Of course, we can also take the time to educate newer users, also. In fact, awareness protects people more effectively than anything I've seen, thus far.
Tuesday, April 25, 2006
Do It Yourself Hacker Kits
The Trojan is even smart and can detect what browser is being used via the user agent and customize the exploit based on the browser settings.
Here is the ad, which was translated into English by Websense:
Dear Friends! We would like to offer you multi-component exploit Web-Attacker IE604, that realizes vulnerabilities in the internet browsers Internet Explorer and Mozilla Firefox. With the help of this exploit you will be able to install any programs on the local disks of visitors of your web pages. In the foundation of work of the exploit Web-Attacker IE0604, there are 7 already-known vulnerabilities in the internet browsers: Objective of the Exploit: Hidden drop of the executable from the deleted source to the local hard drive of the site visitor.
-Bypasses all security measures-Is not blocked by Firewalls [Agnitum Outpost, Zone Alarm, Sygate Personal Firewall]
-Tri-level protection -Flexible installation -Updates -Detailed Statistics
For the full alert, with screenshots, click here.
John Leyden of the Register is also covering this story.
trimMail's E-Mail Battles has an interesting story about why some of these kits are so dangerous. Here is an excerpt:
Smart computer users know that once a computer is infected by a rootkit, it's changed forever. And as Windows rootkits go, Hacker Defender is among the most dangerous. The author of Hacker Defender, holy_father, explains why he does what he does, and what you can do to detect his rootkit.
Antivirus companies sell a fake sense of security, but they do not bring real security to your computer. Antivirus just fights programs that are visible to common users. They don't care about the cause.
Do it yourself kits are becoming increasingly common and are making the Internet increasingly dangerous for the common user.
Here is a recent post, I wrote about "how to scam kits" and one that is designed for use in committing fraud on eBay.
Link, here.
Thursday, April 20, 2006
Package Deals to Commit eBay Fraud
AuctionBytes (Ina Steiner) is reporting:
"According to an "eBay scam kit" obtained by AuctionBytes, women are easy marks on eBay. The kit, marketed as "eBay: Women Dough v1.8," contained everything a scammer needs to set up auctions on eBay to sell items they don't own and don't intend to fulfill to "customers."
"The eBay Women Dough scam kit contained three prepackaged high-end auctions targeting U.S. female buyers. The kit included descriptions and photos to include in the eBay auctions with detailed advice on how to list, handle customer service and accept payments."
These kits even contain detailed instructions on how to bypass eBay controls and dupe the potential victim into using unprotected wire transfer services, such as Western Union and MoneyGram.
Full story, here.
Please note that AuctionByte's article also quoted a Washington Post Article on IRC chatrooms written by Brian Krebbs. This article covers the full spectrum of information that is bought and sold in these chatrooms and paints a pretty realistic picture of the activity.
Here is something, I thought was interesting from the article:
"Marcus Sachs, a former cyber-security adviser to the White House who now directs the Bethesda, Md.-based SANS Internet Storm Center, said that if the information posted by the IRC channel operators is legitimate, then they are likely working with people on the inside at the major credit card issuers. But Sachs said he suspects that by "verifying" credit card information posted by other chat room members, those running the IRC channels are more interested in scamming the phishers."
Full story, here.
I guess we now know where all the stolen information from the record amount of data breaches is going. It's being sold on the Internet.
Here is a previous post, I wrote on that subject (data breaches):
Information Breaches, the Human Factor
