Showing posts with label internet crime forums. Show all posts
Showing posts with label internet crime forums. Show all posts

Thursday, January 11, 2007

New phishing rod being marketed on Internet crime forums

A new and more dangerous "phishing rod" is being marketed and sold in Internet crime forums. This assures that this "phishing rod" will be readily available to all sorts of "i-jackers" (identity theives).

DigitalTransactionNews is reporting:

RSA Security Inc. on Wednesday announced its analysts had discovered a powerful new phishing tool fraudsters are selling via online forums and using to hoodwink consumers. The tool, which RSA calls a “universal man-in-the-middle phishing kit,” allows phishers to set up a URL that can interact in real time with the actual content of the Web site of a targeted brand, such as a bank or e-commerce site. In this way, the fraudsters can intercept any data consumers may enter at the log-in or checkout pages of these sites. They then send out phishing e-mails embedded with links that send recipients to the fake URL, where the user can see an organization’s legitimate Web site but where any information he enters will be hijacked by the fraudsters as he types it.

The new tool is especially insidious, says RSA, because of its all-purpose nature. Fraudsters can use it to target any Web site without having to customize or create a tool for each brand. Also, the tool collects all data users enter, including all information the user types in after logging in. Typically, phishing attacks gather only data they request, usually passwords, PINs, or credit and debit card account numbers.


DigitalTransactionNews article, here.

I first read about the man in the middle phishing attack when it was discovered at CastleCops by PIRT (Phishing Incident Reporting and Termination Squad) and reported by Internet crime writer Brian Krebs of the Washington Post, here.

PIRT is a great place to report suspected phish. They have a lot of dedicated personnel that fight phishing!

It's a shame that these Internet crime forums are allowed to continue operating. It's even been reported that one of them is being "hosted" in the Islamic Republic of Iran.

And Internet crime isn't the only problem that Iran is hosting. I'm sure some of our brave troops in Iraq and Afghanistan could attest to that.

Until we go after the sources of this problem, I have a "bad feeling" that Internet crime will continue to grow.

The FTC was recently given greater powers to follow Internet criminal activity across borders. Maybe laws like these will enable the "good guys" to start having a more "lasting" effect on the people behind the problem.

Tuesday, April 25, 2006

Do It Yourself Hacker Kits

Not too long ago, you needed some technical expertise to become a Internet criminal. Think again, for about $15.00 you can buy your own do it yourself kit from Russia. This kit downloads a Trojan when someone visits the site it is installed on. It logs keystrokes, (which can give someone access to your personal and financial information), downloads additional cybernasties and opens backdoors to a compromised system.

The Trojan is even smart and can detect what browser is being used via the user agent and customize the exploit based on the browser settings.

Here is the ad, which was translated into English by Websense:

Dear Friends! We would like to offer you multi-component exploit Web-Attacker IE604, that realizes vulnerabilities in the internet browsers Internet Explorer and Mozilla Firefox. With the help of this exploit you will be able to install any programs on the local disks of visitors of your web pages. In the foundation of work of the exploit Web-Attacker IE0604, there are 7 already-known vulnerabilities in the internet browsers: Objective of the Exploit: Hidden drop of the executable from the deleted source to the local hard drive of the site visitor.

-Bypasses all security measures-Is not blocked by Firewalls [Agnitum Outpost, Zone Alarm, Sygate Personal Firewall]

-Tri-level protection -Flexible installation -Updates -Detailed Statistics

For the full alert, with screenshots, click here.

John Leyden of the Register is also covering this story.

trimMail's E-Mail Battles has an interesting story about why some of these kits are so dangerous. Here is an excerpt:

Smart computer users know that once a computer is infected by a rootkit, it's changed forever. And as Windows rootkits go, Hacker Defender is among the most dangerous. The author of Hacker Defender, holy_father, explains why he does what he does, and what you can do to detect his rootkit.

Antivirus companies sell a fake sense of security, but they do not bring real security to your computer. Antivirus just fights programs that are visible to common users. They don't care about the cause.

Do it yourself kits are becoming increasingly common and are making the Internet increasingly dangerous for the common user.

Here is a recent post, I wrote about "how to scam kits" and one that is designed for use in committing fraud on eBay.

Link, here.