Showing posts with label keyloggers. Show all posts
Showing posts with label keyloggers. Show all posts

Wednesday, May 28, 2008

We are a long way to full disclosure in data breaches - even if we wanted to be!

I saw an article on PCWorld, written by Robert McMillan (IDG News), that according to the research firm Gartner -- not all data breaches are being reported by retailers.

I thought to myself ... here we go again ... burying our heads in the sand that all personal and financial information is hacked from retailers. Of course, that isn't to say that none of the stolen information is coming from retailers, either.

The conclusion was based on 50 retailers being interviewed and 21 of them saying they had been breached. Of these 21, allegedly only 3 had reported a data breach.

This led me to wonder if any of these retailers do business in an area, where disclosing data breaches is a matter of law?

My humble guess is that in the litigation happy society we live in today, no one is going to report anything unless they have to. As long as no one is certain (or they can get away with saying that) the information is probably buried, or someone comes up with a rationalization that it really didn't happen.

Going a little further, there has to be a lot of information being stolen that no one is even aware has been compromised. The fact that no one is aware it was compromised makes it easier to be used by the criminal element, effectively.

The sad truth is even if you could make computer systems bulletproof, human beings will continue to compromise information, either via social engineering techniques or to obtain financial compensation. We've made some of this information worth a lot of money.

Of course, information thieves often combine technology and social engineering, also. In the mysterious world of information crime, one shoe rarely fits all.

Right after reading the PCWorld article, I happened upon more research from Finjan, which might provide evidence that there must be a lot of computer systems out there that are NOT very "bulletproof."

As stated on Finjan's MCRC blog:

In our recent MPOM report, we reported on a Crimeserver hosting 1.4G of unprotected stolen data, including passwords, medical data, emails etc.

Many people asked us how we found the data. Was the data secure or not?

Although we cannot disclose all information to the public (for obvious reasons), I can say that the data on that Crimeserver was unprotected, meaning anyone could access it.

Today we came across another Crimeserver - it seems that we are finding one every other day...
Additionally, Finjan reported:

As we disclosed in our Q3/2006 Trend report, malicious code is hosted on caching servers of leading Search Engine Providers. This time we reported in our recent MPOM that stolen end-user data is also stored on these caching servers. Yes, your passwords, Social Security numbers, Online banking information …. no data is safe, as the examples below illustrate.

Even more alarming, it didn't take a lot of know-how to access all this information. The people at Finjan were able to do it, using simple Google searches.

I highly recommend taking a look at the entire blog post from Finjan (link provided at the bottom of this page) -- there are some alarming visual presentations indicating how much information is out there.

I'll include one, which shows a compromised (actual info blocked out) SSN:



The blog post also has visual presentations (screenshots) of user names and passwords to internal company sites, porn sites and online banking sites.

Now let me see ... if stolen information is being hosted on unprotected (anyone can access) crimeservers ... and it is being indexed (cached) by search engines ... it's probably safe to assume we don't have any real idea how much stolen information there is out there.

Also, please note it's safe to say not all this information came from retailers.

Last, but not least, I've seen commentary that we should blame Google for all this. First of all, I doubt that Google is the only place this information can be found. Another thing to contemplate is that thinking like this is as narrowly focused as thinking that retailers are to blame for most of the stolen information out there.

Unless we stop blaming each other -- we are going to be a long way from achieving transparency in data breaches. Exposing problems often is the first step in correcting them.

Until we embrace transparency, the people to blame (criminals) are going to be laughing all the to the bank.

Finjan post from their MCRC blog, here.

Wednesday, April 16, 2008

Corporate suits targeted in spear phishing attack!

The mainstream media is reporting that the Phishermen attempted to spear a large number of corporate executive types this week.

This form of phishing is referred to as spear phishing, or whaling. The intent of phishing is to trick an unwary human being into giving up sensitive personal or financial information, which is later used to for illicit purposes. Spear phishing or whaling is simply a more focused approach designed to target more specific targets than everyday run of the mill phishing attacks, which are sent out by the millions via spam spewing botnets.

The New York Times is reporting:

Thousands of high-ranking executives across the country have been receiving e-mail messages this week that appear to be official subpoenas from the United States District Court in San Diego. Each message includes the executive’s name, company and phone number, and commands the recipient to appear before a grand jury in a civil case.

If any of them clicked on the link directing them to a view of the full subpoena, they probably downloaded malicious software with keylogging capabilities. Once this is dropped on a system, keystrokes are recorded and transmitted back to the criminals behind the attack.

The normal intent when this done is to commit financial crime, but given the targets in this attack, corporate espionage (information theft) could be the intention, also.

The malware bundle allegedly places the victim's computer under the control of the phishermen. When this occurs, the infected computer is often referred to as a zombie.

The latest attack has prompted warnings to be placed on the websites of two California Federal Courts, as well as, the administrative office of the United States Courts.

The New York Times article speculated that this attack was of Chinese origin, while Brian Kreb's article in the Washington Post speculated the attack could be of Romanian origin. Both of these speculations came from noted industry security experts. Unfortunately in the world of cybercrime, the activity often so anonymous, all the rest of us can do is speculate as to who might actually be behind it.

Please note that speculating that the activity might have come from either China or Romania is probably a good deduction. Both countries are known to host a lot of criminal activity of a cyber nature.

It is also being reported that not all the security products out there will detect this attack.

I guess that the only solace from this fact is that if you can teach the user to recognize the social engineering aspects of these attacks, they aren't going to click on the link and infect their system.

Even though "fear" is well-known social engineering technique, if you examine the attack it doesn't make very much sense. After all, the last time I checked, a subpoena delivered via electronic communication wouldn't be legally binding. It's probably a no-brainer that federal courts wouldn't issue a subpoena via an e-mail.

Sadly, more employees fall for phishing attempts than many might realize. In fact, some organizations are now testing their own employees with scary results. Most recently, this was done by both the U.S. Army and the IRS.

Update 4/19/08: The FBI announced that a new phishy e-mail is circulating regarding a grand jury summons. Not sure if this is a tie in, but as Alex Eckelberry lamented on the Sunbelt blog -- phishing attacks are becoming more specifically targeted and the intent might be more than to steal financial information. Of course, that's not to say there isn't financial motivation involved, there normally is.

Friday, December 07, 2007

Has hacking become too easy? Ask the child predator who just got 110 years for doing it!

Here is a hacker, who ended up in a lot of trouble after using malware to blackmail underage girls into creating pornography of themselves. The problem is it was probably a little too easy for him to obtain the tools, he used to pull his "hack" off!

This leads me to be slightly cynical that putting one person behind bars for 110 years is going to solve the overall problem, we are facing with the irresponsible use of technology.

Picked up this up from Sharon Gaudin (Computer World) courtesy of the NY Times:

A North Carolina man last week was sentenced to 110 years in prison after admitting that he and a co-conspirator hacked into computers used by young girls and used illicitly gained data to blackmail them.

Ivory D. Dickerson, 33, a civil engineer, admitted that he conspired with the other person to send emails or instant messages to underage girls as part of a scheme to trick them into opening a file containing the Bifrost trojan horse. The malware would give Dickerson and his co-conspirator control over the victim's computer, and they tried to use hacked information to coerce the girls into creating and then electronically sending them lurid photos of themselves, prosecutors said.

Dickerson used all the normal techniques to monitor his victims, such as keylogging software. He also had a tool, which enabled him to hack into web cameras and record what was going on.

This concerned me from a privacy perspective so I decided to see what would pop-up if I Googled "hacking webcams." To my utter amazement, I found some shocking results, which are pretty scary.

In fact, one site has a tutorial on how to hack webcams, using a Google search string.

In most instances, this can be prevented by password protecting whatever camera system you install.

Please note that criminals could use your cameras against you in a variety of ways that threaten both your privacy and safety.

Going back to the article about our hacker using BiFrost malware, a Sophos rep is quoted as saying:

The Bifrost malware, "is relatively easy to obtain," said Richard Wang, manager of SophosLabs U.S. "It's not something you need to pay for. Since we first saw it in April of 2005, we've seen over 1,200 different versions of this Trojan. The guys who write them are always trying to put up new versions to hide them from anti-virus software."

I'm guessing that Mr. Wang means the malware can be obtained from one of the hacking forums that seem to be out there (pretty easy to access) on the Internet.

So far as Mr. Dickerson, lock him up and throw the key away, preferably on a deserted island. Saying that, here is yet another example that it doesn't take a whole lot of skill to be a hacker nowadays. In fact, it seems to be a little too EASY!

It's a shame that parents now have to become computer security experts to ensure the safety of their children. Maybe the answer is to take a hard look at all the enabling factors we seem to see too much of these days?

ComputerWorld article (courtesy of the NY Times), here.

Fox News has a pretty telling video about the subject of webcam hacking, which can be seen, here.

Saturday, September 08, 2007

SIRAS PI - tracking theft to the source


Graphic demonstration of anti-theft technology courtesy of SIRAS.com.

Criminals, who steal goods, whether with bogus financial instruments, or by more physical means might be in for a little surprise if the merchandise is protected by SIRAS PI.

Last week, SIRAS made this announcement in a press release:

SIRAS.com, the pioneer in Point-Of-Sale Electronic Product Registration used by leading manufacturers and retailers, has announced the nationwide launch of SIRAS P.I., a groundbreaking initiative to aid law enforcement officials in determining whether products they recover are, in fact, stolen, and if so, from where. Piloted by the Mesa, Arizona Police Department, SIRAS’s P.I. (Product Information) Database has already proven to be effective in helping law enforcement officials identify stolen items, report suspicious items, and apprehend and convict thieves. The database will be available, free of charge, to police and law enforcement agencies nationwide.

The way SIRAS works is simple, but effective. It tracks a product by recording the UPC (Universal Product Code) and the product serial number. SIRAS has the capability to determine where merchandise was stolen, whether from a merchant, manufacturer, or individual.

Earlier this year, SIRAS did some testing that revealed a substantial reduction in TV and MP3 player losses on products, where their technology was being used.

If deployed properly at the merchant level -- it could also determine how an item was purchased, and whether or not -- the method of payment used was legitimate. In theory, a merchant could also use the technology to impact credit card chargeback and fraud check losses.

I say "deployed properly" and "in theory" because the information to accomplish this (sales data) belongs to the company using SIRAS technology. Because of this, the capability to track sales information would have to be implemented inside the company. At most larger companies, this information is already tracked and analyzed to prevent and detect dishonest activity.

For years, most high-theft (shrink) merchandise has been secured so a thief can't merely pick it up from a shelf. When high-theft merchandise that was secured is stolen, it's normally because of one of two reasons. It was purchased with a bogus financial instrument, or an insider was involved in the theft.

Other reasons for secured merchandise being stolen might be a theft, directly from the manufacturer, or a theft during the shipping (transport) process. In these instances, if the merchandise was registered at the manufacturer, SIRAS can identify the point of compromise, also.

Technology has made it a lot easier for criminals to obtain and use fraudulent forms of payment. Information being compromised (data breaches) and anonymous places to communicate like Internet chat rooms, have given a lot of common criminals access to bogus financial instruments.

Along with the increased availability of fraudulent forms of payment, obtaining counterfeit identification documents has become fairly easy, and the identity used on them normally belongs to someone else. This has made it easy for a lot of retail criminals to operate as someone else.

Because of these new trends, current systems that record personal information to prevent fraud are becoming less effective than they use to be. I often wonder (no one probably really knows) how much of the information contained in them is incorrect.

In the recent data breach at TJX, one of the systems compromised was their refund database. Stories have circulated recently about the wrong people being pegged as frequent refunders, or bad check writers after their identities were stolen.

Neither one of these situations fosters good will, or trust with customers. Besides that, data breaches are becoming costly. The last I heard TJX has spent approximately $256 million dealing with the breach. With pending litigation, the cost is liable to keep going up.

With SIRAS, using personal information isn't necessary to determine, whether or not, a return is legitimate. SIRAS already has proven to be highly effective in reducing refund fraud without asking for one item of personal information.

An example of how some of the TJX data was used in a retail theft scenario can be seen, here.

Given that criminals that steal merchandise want to turn it into money, two methods are normally used. They either refund it somewhere, or fence it. Auction sites provide an easy and when combined with account-takeover activity (anonymous) venue for criminals to fence merchandise.

In the auction world, seller accounts are taken over all the time. This normally occurs when seller accounts are compromised by a phenomenon known as phishing. Phishing occurs when a person is tricked into giving up their access information after receiving a spam e-mail.

Compromised seller accounts are sold on the Internet the same way financial information is, and there is a trend in DIY (do-it-yourself) phishing kits being sold that enable non-technical criminals to get into the game.

eBay and PayPal are two of the most heavily phished brands. Once these accounts are compromised (taken over), they are used by criminals to fence merchandise and launder the monetary proceeds of their illicit sales.

Another growing trend related to phishing is when malware, also sometimes known as crimeware is used to steal information. The difference here is information is stolen from systems automatically (normally by keylogging software) and social engineering (trickery) is no longer necessary to get people to give up information.

Malware is often picked up by a computer system by clicking on a spam e-mail link, or by visiting a website designed to inject the software on a system. PC World recently did one of the many stories floating around about malware being sold on the Internet in the form of DIY kits.

In the story they wrote:

The global market for criminal malware now operates like a supermarket, complete with special offers and volume discounts, a security company has discovered.

Here again, this capability enables not very technically inclined criminals to get into the game. This has become a growing problem and I expect it to get worse before it gets better.

With the availability of all this personal and financial information, being sold on an economy of scale, current fraud protection systems are routinely being compromised by a lot of criminals.

There is an old saying in the investigations world, which is if you want to solve a crime, the easiest way is to follow the money.

SIRAS takes this one step further by tracking both the merchandise and can track the money ( if programmed to do so by the user). When you do this, the odds are far greater that the true culprit will be identified. They are normally associated with either the money, and or the merchandise.

Since the technology records both physical and UPC information, the database can determine exactly where the merchandise was compromised (stolen). Given that many merchants use digital video systems -- which are capable of storing video footage for a long time, it's also possible to obtain video evidence of the original transaction -- when sales information has been programmed to tie into the technology.

SIRAS has been used by select manufacturers and merchants for several years now -- however a new initiative, SIRAS PI, which was tested with Mesa PD -- makes the database available to law enforcement agencies free of charge.

Law enforcement can access the database either via the Internet, or by telephone. They can also add items to the database when they are reported stolen. If someone later tries to refund the merchandise at a participating retailer, the transaction can be automatically flagged.

Although a lot of fencing now occurs on the Internet, the technology is equally as effective in investigating more traditional property crimes, also. The bottom line is once merchandise is discovered, it can be tracked by SIRAS, if the item has been registered.

Recently, Chris Hansen (MSNBC), did a story about iPod theft. When Apple was approached about tracking the merchandise using Apple's registration database, they decided not to cooperate with MSNBC.

Undaunted by this, MSNBC purchased a bunch of iPods and engineered the registration disc to send them the information when the iPod was registered. They then left the iPods (new in the box) unattended, let them get stolen and tracked them to the crooks once the iPod was registered.

Chris Hansen made an excellent point on how databases can track stolen merchandise -- but in this instance, brand new iPods had to be left in public places to be stolen -- then registered to make the point.

If Apple used SIRAS technology to protect their merchandise -- it would have already been traceable, even if it was stolen from an individual -- who didn't provide the thief with the registration disc. It also would eliminate privacy concerns, which might be why Apple didn't want to cooperate with the MSNBC investigation?

When registering any product, a lot of personal information is normally asked for.

In any event, most criminals of the smarter variety aren't going to provide their personal information in the registration process. Most of them shy away from doing things, which might get them caught.

It would be interesting to have MSNBC, or another investigative news source do the same story with merchandise protected by SIRAS. The story might expose more than people, who stole because of an almost "too good to be true" opportunity was provided to them.

MSNBC iJacking story, here.

This brings up another potential benefit to this technology. Expensive portable electronics and other expensive toys like mountain bikes are stolen from the people who buy them (customers) all the time. Using SIRAS technology might even be a selling point that instills customer trust in the product they are purchasing.

This technology has prevention/investigation applications for corporations, law enforcement agencies and individuals, alike. It also doesn't require using people's personal information, which isn't as effective as it used to be, and is becoming more unpopular all the time.

In my opinion, this technology has the ability to make it a lot harder to get away with stealing merchandise and converting it into money.

Of course, the more it is used, the more effective it will become. Databases have a tendency to do this, or become more useful as they contain more information.

There are a lot of anti-theft/fraud technologies that claim to prevent theft/fraud. Very few of them also claim to be able to go after and hold the criminals committing the fraud/theft personally accountable.

The last I heard, most criminals still fear getting caught!

If you would like more information on the organized trade in counterfeit identification documents, the story of Suad Leija can be seen, here.

Suad's story has been covered extensively in the media, including by Lou Dobbs. Currently, she is writing a book and I keep in touch with her occasionally.

More information about bogus financial instruments can be seen, here and here.

A chronology of data breaches is compiled by the Privacy Rights Clearinghouse, here.

The best source on phishing is the Anti-Phishing Working Group and if you are interested in learning even more about phishing and want to see some totally fake banking sites, Artists Against 419 is another good place to visit.

Last, but not least, if you are interested in learning more about SIRAS PI, you can do so by visiting their site, here.

Sunday, July 01, 2007

Phishermen impersonate DOJ in spam e-mail



DOJ logo. The press release mentions that the e-mail contains their official logo. Copying graphics is extremely easy to do. Internet criminals do this to make their spam e-mails look more official, or even to create totally spoofed (impersonated) websites.

Recently, Internet Phishermen have spoofed the IRS, FTC and the FBI to trick people into giving out personal/financial information. Of course, they spoof a lot of other organizations, also.

Apparently, the e-mail even contains the DOJ logo on it. This isn't very hard to do because copying graphics takes very little technical skill. To demonstrate, I will copy the DOJ logo and place it at the top of this post.

Because this is so easy to do, a lot of fake websites (mostly financial institutions) are all over the Internet.

From the DOJ press release dated June 27th:

The Department of Justice has recently become aware of fraudulent spam e-mail messages claiming to be from DOJ. Based upon complaints from the public, it is believed that the fraudulent messages are addressed "Dear Citizen." The messages are believed to assert that the recipients or their businesses have been the subject of complaints filed with DOJ and also forwarded to the Internal Revenue Service. In addition, such email messages may provide a case number, and state that the complaint was "filled [sic] by Mr. Henry Stewart." A DOJ logo may appear at the top of the email message or in an attached file. Finally, the message may include an attachment that supposedly contains a copy of the complaint and contact information for Mr. Stewart.

Although most phishing attempts are designed to trick people into giving up their personal/financial information, malware (crimeware) automates the process. Here is what the DOJ has to say about that:

Computers may be put at risk simply by an attempt to examine these messages for signs of fraud. It is possible that by "double-clicking" on attachments to these messages, recipients will cause malicious software – e.g., viruses, keystroke loggers, or other Trojan horse programs – to be launched on their computers.
Press release with links of where to report these phishy e-mails, here. There are also some links to government sites designed to educate the public on Internet crime on the news release, also.

If you would like to see how easy it is to copy graphics and make a fraud website look like a legitimate one, Artists Against 419 has a lot of actual examples on their site (see Lad Vampire link), here.

The Anti Phishing Working Group compiles statistics on spam and phishing. Every time they issue a new report (monthly), a new record seems to be set. APWG site, here.





Graphic illustration of what might happen to your computer after "double clicking" on an e-mail attachment from the Phishermen (courtesy of the FBI)!

It appears even the FBI has a sense of humor! Great picture (my opinion).

Sunday, June 10, 2007

The Phishermen keep using the IRS name to hook Phish (Identity Theft Victims)

Phishing has become a huge problem. Criminals (phishermen) spoof (impersonate) a brand or organization that people trust to trick people into giving up their personal, or financial information. The information is then used to steal money.

In the more sophisticated attempts, malware (crimeware) is dropped on a system that logs keystrokes, gathering even more personal information, without the computer owner's knowledge, or consent.


The phishermen have been spoofing the IRS so frequently, the IRS set up a dedicated e-mail address to report activity. The address is phishing@irs.gov (follow the instructions).


The most recent version is a spam e-mail intended to scare a person into thinking they are being investigated. Here is what the IRS site is reporting:


The e-mail purporting to be from IRS Criminal Investigation falsely states that the person is under a criminal probe for submitting a false tax return to the California Franchise Tax Board. The e-mail seeks to entice people to click on a link or open an attachment to learn more information about the complaint against them. The IRS warned people that the e-mail link and attachment is a Trojan Horse that can take over the person’s computer hard drive and allow someone to have remote access to the computer.


Trojan horses are often a gateway to install malware -- sometimes referred to as crimeware -- which often includes keylogging software. The bottom line is that once installed on a computer, they have the ability to steal personal and financial details, from afar, without any additional assistance from you.


All the terms out there get confusing to non-technical people, there are some now saying, we should group some of the terms together and call it "grayware?" Another term to group some of this terminology together is "badware."


Similar technology is used for advertising and marketing purposes by legitimate businesses, also. This is often referred to as spyware and adware. The one thing they all have in common is that they are often a nuisance.


The key is to NOT even open the spam e-mails enticing you to click on their links. The best practice is to delete them. These e-mails are generated by the millions, perhaps billions by now, using automated software and botnets (other people's computers that have been taken over).


Spam filters designed to stop them from getting in your inbox, seem like they are getting less effective, recently.


Botnet owners are known to rent out their networks to other criminals for this purpose.


Sadly enough, the IRS name has been being spoofed a lot lately. Here is the extent of it:


Since the establishment of the mail box last year, the IRS has received more than 17,700 e-mails from taxpayers reporting more than 240 separate phishing incidents. To date, investigations by TIGTA have identified host sites in at least 27 different countries, as well as in the United States.

The phishermen often impersonate financial institutions, eBay, PayPal, or government agencies; such as the FBI and Interpol.


The latest alert from the IRS can be seen, here.

Friday, May 04, 2007

FBI warns of banking details being i-jacked (stolen) at Internet cafes and hotel business centers

It could be pretty expensive to check your online banking assets at Internet cafes, or at the public computer in a hotel's business center.

Here is an interesting article by Robert Schmidt at Bloomberg.com, quoting FBI sources, where he says:

Tens of millions of dollars have been looted from online brokerage accounts in a fast-growing fraud that targets unsuspecting hotel guests and Internet cafe patrons, Federal Bureau of Investigation officials say.

The way this is done isn't new, the crooks simply install keylogging software on these public machines. As I've written before, keylogging software (itself) is legal and can be purchased by anyone over the Internet. Some of the legal (marketing) justifications are to spy on employees, spouses and your children.

Oh I forgot, they are also used by private investigators, like the ones busted in the recent HP scandal.

Keyloggers are often dropped (installed) on computers via spam e-mails, when an unsuspecting person clicks on the wrong link, also. According to the Anti-Phishing Working Group, the use of them is growing, rapidly. February set an all time record for this type of activity, according to their monthly report.

Although keyloggers are legal, when used by criminals to steal personal and financial information, we refer to them as crimeware (go figure)?

To read the full article at Bloomberg.com, click here.

I wonder if the FBI's job would be easier if laws were enacted to stop certain companies from enabling this growing problem?

Monday, April 30, 2007

E Gold accused of being a money laundering vehicle for financial fraudsters and child pornographers

To anyone familiar with crime on the Internet, allegations of criminals using, or manipulating E Gold are nothing new. Like wire transfers, E-Gold gives their customers the ability to transfer the value of gold, electronically. To transfer the gold's value, all anyone needs is a e-mail address, account number and password.

Because of this, the accounts can be prone to phishing, and or crimeware (malware) attacks, using keylogging software. When this happens, the phishermen clean out the account and transfer it, elsewhere. E-Gold's terms of service stipulate that once a transfer is done, it cannot be reversed.

It should be noted that Internet criminals use wire transfer services (MoneyGram, Western Union) for the same reason -- they provide a lot of anonymity.

Apparently a task force from the Department of Justice has been looking into the money laundering angle, and is charging E Gold with several federal charges.

Here is a summary of the action against E Gold from the DOJ press release:


A federal grand jury in Washington, D.C. has indicted two companies operating a digital currency business and their owners on charges of money laundering, conspiracy, and operating an unlicensed money transmitting business, Assistant Attorney General Alice S. Fisher of the Criminal Division and U.S. Attorney for the District of Columbia Jeffrey A. Taylor announced today.


The basis of the DOJ charges are:



The indictment alleges that E Gold has been a highly favored method of payment by operators of investment scams, credit card and identity fraud, and sellers of online child pornography. The indictment alleges that the defendants conducted funds transfers on behalf of their customers, knowing that the funds involved were the proceeds of unlawful activity; namely child exploitation, credit card fraud, and wire (investment) fraud; and thereby violated federal money laundering statutes. The indictment further alleges that the defendants operated the E Gold operation without a license in the District of Columbia or any other state, or registering with the federal government, and thereby violated federal and state money transmitting laws. The indictment alleges that this conduct occurred at various times from 1999 through December 2005.


It appears a lot of different federal agencies worked on this investigation:

The case is being investigated by the U.S. Secret Service with the assistance of the IRS and the FBI. The case is being prosecuted by the U.S. Attorney’s Office for the District of Columbia and the Computer Crime and Intellectual Property Section of the Criminal Division. Assistance is also being provided by the Child Exploitation and Obscenity Section and the Asset Forfeiture and Money Laundering Section of the Criminal Division.


Full DOJ press release, here.

Besides allegedly being used to launder money, E Gold is often used in advance fee and auction scams, which trick people into sending their hard earned cash to fraudsters. I've written about the auction, secret shopper, romance, lottery and job variations of advance fee scams on this blog, frequently.

Like the problems with accounts being phished, or their value being drained because of crimeware, little can be done once the gold (converted to a monetary value) has been transferred.

When password details can be stolen, accounts can be taken over, also. This happens happens frequently on auction sites; when trusted accounts are compromised, then used for fraudulent purposes.

Wikipedia has an extensive article about Advance Fee (419), here.

It will be interesting to see how this plays out!

Tuesday, April 10, 2007

Blog exposes risk in reporting ID Theft

(Screenshot courtesy of the In Security Blog)

I'm surprised no one has called this one out before. John Sharp, author of the In Security Blog writes:

Those of you who follow my blog know that I'm worried about the increasing sophistication of keyloggers. Which is why, when I went on the FTC site this morning, I was a little shocked to discover that the format of the FTC ID Theft Complaint Form presents a veritable gift to keyloggers.

Full post from the In Security Blog (great read), here. There are also some great tips on how to avoid becoming a crimeware victim on the PR release on this from Authenium (John's company), here.
John's concerns are well founded. The Anti Phishing Working Group, which tracks phishing, malware and crimeware (normally keylogger variants) shows their use increasing, monthly.
Keyloggers (once on a system) record keystrokes, sending them back to the person, who covertly placed the software on the system. Criminals often install (drop) these cybernasties using spam e-mails, which lure people to click on their links.
The information, the criminals intend to log (steal) is personal and financial, which is then used to steal money.


(Chart courtesy of Websense and the APWG)


Sadly enough, keylogging software has so-called legitimate uses and can be legally purchased by anyone. One of the legitimate (so-called) uses is to spy on other people (invade their privacy).

Just about anyone can buy this wonderful technology right on the Internet, which can bee seen, here. Perhaps if it wasn't so easily available, the problem wouldn't keep getting worse?

The FTC does a lot of good in their battle to fight identity theft. You can get a lot of good information about how not to become a victim by visiting their page on it, here.

Once a computer has been compromised with crimeware (keylogging software), anything entered on it can be logged (exposed). Even if the site you are sending the information to is "secure," your computer IS NOT!

The Internet is full of sites requesting your personal details, the bottom line is to make sure your system is secure, or if it IS NOT - avoid sending personal or financial details, anywhere.

Saturday, April 07, 2007

buySAFE takes on the issue of counterfeit (knock off) merchandise

buySAFE bonds sellers after verifying they are reputable and honest. They also contribute their time to protecting the average person in the sometimes murky waters of e-commerce. Recently, buySAFE has been taking on the (huge) issue of counterfeit merchandise.

Consumers are protected when they buy from a merchant bearing the buySAFE seal. Not a very bad deal for the consumer! Bonding isn't free, but many merchants experience higher sales volumes after being accepted by buySAFE. Trust can drive a lot of sales! buySAFE is also a viable means for a merchant to protect their assets.

The Association of Certified Fraud Examiners noted in their last report to the nation that small businesses suffer "disproportionate fraud losses," when they are victimized by fraud. Large merchants can afford experts to deal with their fraud problems, however the cost is hiring experts can be restrictive for smaller merchants.

Of the numerous fraud issues found on auction sites, complaints about counterfeit goods rank pretty high. People buy items believing they are the "real deal," only to discover the item is a (knock-off) counterfeit.

Companies, who sell respected and trusted brands, are impacted by a loss of sales and consumer trust in their products, also. Some of them have already filed civil litigation against eBay because of the amount of knock-off (counterfeit) merchandise being sold on the site.

Even though auction sites offer seller rating systems, these ratings are often compromised when seller accounts are hijacked (taken over). eBay and PayPal (by most accounts) are recognized as the two most phished brands out there.

The intent of most of these Phishing schemes is to obtain personal/financial information to steal money (and or) take over legitimate accounts.

This can also happen when malware (crimeware) is inserted into an unprotected system and personal/financial details are stolen, normally using key logging software. Sadly enough, the criminal element has found it pretty easy to remain anonymous on auction sites, and few of them seem to get caught.

Whenever the Anti Phishing Working Group (APWG) releases a new report, both of these activities seem to set a new record that surpasses the previous one.

Recently, eBay seems to be taking the fraud problem a lot more seriously, but someone using the name of "Vladuz" is intent on proving their systems are easily compromised. A good place to keep up on the Vladuz saga is firemeg.com.

Although a good information source, I'm not certain that bashing Meg is the solution to fraud on auction sites.

Being the largest auction site, eBay is targeted by fraud all the time because of their popularity.

Fraud has already migrated to other auction sites, but they will always target the most popular.

The reason for this is simple (and it's only business for them) - there are more victims to harvest in popular places.

The term "Vlad" was based on a Romanian historical figure, Vlad Tepes, who inspired the novel, Dracula. In recent times, the term has come to signify fraudsters from Romania, who are well established and organized in the world of auction fraud.

Besides, protecting merchants and consumers, buySAFE makes a lot of contributions to addressing fraud issues on auction sites. Most recently, Jeff Grass (buySAFE CEO) has posted a lot of educational information on his blog about the counterfeit problem, here.

Jeff also appeared on the Today show, when they did a piece on counterfeit goods.You can view a clip of the show, here.

And the Today show isn't the only place that considers buy Safe’s views on the counterfeit problem important. The French government recently included buySAFE as part of a U.S. delegation (including government experts) to discuss the problem of counterfeit goods.

The INTERNATION ANTICOUNTERFEITING COALITION (a non-profit) sums up the problem when they state:

Counterfeiting is big business.It is estimated that counterfeiting is a $600 billion a year problem. In fact, it's a problem that has grown over 10,000 percent in the past two decades, in part fueled by CONSUMER DEMAND.

The real truth is people who purchase counterfeit merchandise risk funding nefarious activities, contributing to unemployment, creating budget deficits and compromising the future of this country in the global economy.

IACC site, here.

Part of the reason the activity has grown 10,000 percent is probably due to the explosion in e-commerce, especially on auction sites.

buySAFE seems to be doing a little more than just selling a product. In fact, they seem to be exercising some corporate responsibility by educating the public on fraud trends in the rapidly growing world of e-commerce.

Consumers can become a member of their Smart Buyer's Club, which leads you to a lot of good deals (safe to buy), here. Club members accumulate points, which can be redeemed for goods, or services (listed on the site).

Anyone claiming to be a buySAFE merchant can be verified, which can be done on the site, also.

Monday, January 22, 2007

McAfee reports on worldwide identity theft trends

Although, identity theft has become a global issue, there are very few studies that put the trends together from a global perspective.

Since identity theft can travel thousands of miles with the click of a mouse (or with the use of automated software), we could learn a lot by studying the problem as a whole.

McAfee has just released a white paper, which does this.

From the McAfee site:

According to the report, the number of keyloggers - malicious software code that tracks typing activity to capture passwords and other private information - has increased by 250 percent between January 2004 and May 2006. Additional findings show that the number of phishing alerts tracked by the Anti-Phishing Working Group has multiplied 100-fold over the same period of time. The report also provides practical guidelines that minimize the risk of identity theft to help readers protect themselves and prevent this increasingly common crime.

The study shows that identity theft exacts a high toll on national economies around the world. According to the Federal Trade Commission, the annual cost for consumers and businesses in the United States alone reaches $50 billion annually(1). In the United Kingdom, the Home Office has calculated the cost of identity theft to the British economy at $3.2 billion during the last three years(2) and some estimates from the Australian Centre for Policing Research place the cost of identity theft at $3 billion each year(3).

The conclusion of their report is:

We must first admit that every one of us—individuals and businesses—are threatened and potentially vulnerable to identity theft; this is not something that happens only to others. Despite the seriousness of current incidents and the
increasing threat, some basic principles allow us to significantly reduce the risk. Awareness is the best defense. Through awareness, we develop our senses to spot identity theft and to protect personal and corporate information, while maintaining the benefits of information technology.

Not only covered in the report are technological means in which identities are stolen and used, but it also covers known cases, such as "dumpster diving, mail theft and employee theft."

It also shows how victims are denied credit, identification and even labeled as "terrorists" because their identity had been assumed, and used for "illicit" purposes.

The paper is substantiated by referencing a lot of (worldwide) government and private studies.

The paper also has a lot of relevant tips for both individuals and organizations on how to avoid becoming a victim.

All in all - a very "interesting" read.

McAfee White Paper, here.

Friday, October 13, 2006

Cyber Crooks Targeting Online Brokerages

According to the SEC (Securities and Exchange commission) - reports of fraud involving online brokerages are on the rise.

MSNBC reports:

The Securities and Exchange Commission said it had received a surge in the number of complaints about online account break-ins by hackers "in the last few months".

John Stark, chief of the regulator's office of internal enforcement in existence since 1998 said: "We have had more investigations in this area than we've ever had before."

Asked why the phenomenon had grown, he told the Financial Times: "It's easier with all the spyware and keystroke logging programmes have become easier to use, and more ubiquitous. More and more people are doing things online as well."
MSNBC story, here.

Of course, account takeovers are nothing new, criminals have done this for years with credit card, banking and more recently eBay and PayPal accounts.

And keyloggers (which in my opinion should be illegal) continue to be sold (unregulated) on the Internet, see here. Interestingly enough, they are often "touted" as a "do it yourself" investigative tool.

Besides being the inspiration for criminal acts - a lot of people's privacy is probably being violated with some of these technologies. The recent HP scandal is a good example, where corporate executives and private investigators used similiar technology.

Sadly enough - there is too much (currently legal) technology out there that is being abused - despite the growing number of people being victimized by it.

Saturday, September 30, 2006

HP Investigators Used the Same Tools as Phishermen and Fraudsters

Technology has taken away a lot of personal privacy. We often "cringe" when fraudsters and phishermen try to steal our personal information, but the sad truth is that there are many "so called" legitimate people out there doing the same thing.

Jon Schwartz of USA Today reported:

In snooping on a reporter to pinpoint internal news leaks, Hewlett-Packard used high-tech tools common to spammers, phishers, retailers, suspicious employers and investigators.

Those tools, including phishing-style e-mail and tracing software, underscore the growing use of electronic surveillance to monitor consumers' every digital move, computer-security experts say.

Misleading e-mails from HP investigators to CNet reporter Dawn Kawamoto "smacked of phishing tactics" to trick her into divulging information, says Dave Jevans, chairman of the Anti-Phishing Working Group.
USA Today story, here.

What the computer security experts might be referring to are "keyloggers."

If you would like to see how (anyone) can use this technology, link here.

Unfortunately, it doesn't take a private investigator, or computer security expert to electronically invade someone's privacy.

My question is - with the abuses of this technology - why is it legal?

Wednesday, July 19, 2006

Criminals Using Text Messaging to Commit Cybercrime

If you receive a "text message" saying you've been signed up for a dating service (automatically billed to your cell phone) "take a deep breath" before following their instructions.

The Internet Crime Complaint Center (IC3) is reporting:

The FBI has been alerted to a newly discovered malware located at http://www.irrealhost.com. Malware is software designed to infiltrate or damage a computer system without the owner's consent.

The identified malware lures victims to the site through the receipt of an SMS message on their cellular phone. An SMS message is a Short Message Service that permits the sending of short messages, also known as text messages. The message thanks the recipient for subscribing to a dating service, which is fictitious, and states the subscription fee of $2.00 per day will be automatically charged to their cellular phone bill until their subscription is canceled at the online site.

Recipients visiting the site http://www.irrealhost.com to cancel their subscription are redirected to a screen where they are prompted to enter their mobile phone number, then given the option to run a program which is supposed to remove their subscription to the dating service.

When the run option is selected on the Web site, the executable adds several files to the host and changes registry settings to open a backdoor port and lower Windows security settings. The host file is modified to prevent the victim from browsing to popular anti-virus Web sites. The executable also turns the infected computer into a "zombie" network, which can be remotely controlled by the hackers.

For the alert link, here.

In case, you are like me and need clarification on some of the "technical terms," here are descriptions. New terms for computer fraud, such as "vishing" come about all the time and it's hard for the average person to keep up.

Wikipedia is probably the best (most up to date) reference (for new IT terms), I have found, thus far.

Malware is sometimes called crimeware and zombie networks (botnets) are known to be used by cybercriminals for nefarious purposes.

A keylogger could even be installed by visiting one of these "rogue websites." These programs record all the "keystrokes" on a computer and send them (electronically) to the person who installed them on a system. Keyloggers are actually legal and marketed as a means to spy on your loved ones, or anyone else. Criminals use them to record your access information to financial accounts and then steal the money out of them.

If you spot this activity - besides taking a deep breath and not following through with the request - the best thing to do is report it. You can report it to the Internet Crime Complaint Center (IC3), here.

The sad thing is that those of us who know - often just ignore the attempt - which leaves those of us (who don't know) vulnerable.

Sunday, May 07, 2006

Internet Crimes are On the Rise and Deadlier than Ever

Panda Software recently issued it's quarterly report, which comes to the frightening conclusion that 70 percent of all malware they detected in the first quarter of 2006 is related to cyber crime. Activity also seems to have hit record numbers!

Here is their summary:

This report confirms the new malware dynamic based on generating financial returns. Spyware, Trojans, bots and dialers were the most frequently detected types of malware between January and March 2006. Trojans accounted for 47 percent of new malware examples during the first quarter of 2006.

Seventy percent of malware detected during the first quarter of 2006 was related to cyber crime and more specifically, to generating financial returns. This is one of the conclusions of the newly published PandaLabs report, which offers a global vision of malware activity over the first three months of the year. Similarly, the report offers a day by day analysis of the most important events in this area. This report can be downloaded, free of charge, here.

Since this statistic interested me, I jumped over to the Anti-Phishing Working Group's page to see what they had to say. Please note that Panda, along with Websense and MarkMonitor share information with the APWG. They confirmed Panda's report that crime on the Internet seems to be at an all time high.

Here is a tickler from their report:

The total number of unique phishing reports submitted to APWG in March 2006 was 18,480, the most reports ever recorded. This is a count of unique phishing email reports. March 2006 continues the trend of more phishing attacks and more phishing sites. The IRS phishing attack doubled in volume in March as compared to February (in the USA, the tax filing deadline was April 17 in 2006, as the usual April 15 deadline fell on a weekend this year.)

Link, here.

Two of the most concerning forms of malware being used are Keyloggers and Redirectors. Keyloggers are a form of spyware, which record all the strokes on a computer and transmits them to back to the person (criminal), who installed the malware. They are normally used to steal financial information, used in identity theft schemes.

Sadly enough, Keyloggers are legal and easily bought anywhere, including the Internet. They allegedly have legitimate uses like spying on other people?

Perhaps, the FTC should go after some of these vendors like they recently did with the Private Investigators selling telephone records?

Redirectors are a trojan, which once installed on a computer, redirect the user to malicious sites, where their financial information is stolen. The sites are also known to download more malware (crimeware) on systems. Redirectors are extremely dangerous because there is little indication you are being hijacked.

The Anti-Phishing Working Group has some excellent educational information on this subject, including what to do if you become a statistic:

How to Avoid Phishing Scams

What To Do If You've Given Out Your Personal Financial Information

Too many people (who know what to look for) ignore and delete phishing attempts. There are a lot of places you can report activity and make an impact. In most cases, it only takes a minute or two to do so.

You can report phishing activity to the APWG, here. Activity can also be reported to PIRT, which is a joint venture by Sunbelt Software and CastleCops.

Another resource to report activity is the Internet Crime Complaint Center, which is associated with the FBI. You can report it a lot of places, but it is important to report it. If everyone took the time to report one phishy email a day, it would probably have a significant impact.

By reporting the activity that we see and taking advantage of the mostly volunteer efforts to fight it, we might make the Internet a safe place for everyone again. As access becomes cheaper and more widespread, the number of potential victims is growing at a record rate.

Continuing to ignore all those "Phishy" e-mails will only encourage the Phishermen to move forward with greater frequency. Additionally, the attacks are becoming more sophisticated and "how to kits" are being sold on how to do these dirty deeds. This will undoubtedly bring more and more Phishermen to the (already) murky waters of the Internet.

Of course, we can also take the time to educate newer users, also. In fact, awareness protects people more effectively than anything I've seen, thus far.

Tuesday, April 25, 2006

Do It Yourself Hacker Kits

Not too long ago, you needed some technical expertise to become a Internet criminal. Think again, for about $15.00 you can buy your own do it yourself kit from Russia. This kit downloads a Trojan when someone visits the site it is installed on. It logs keystrokes, (which can give someone access to your personal and financial information), downloads additional cybernasties and opens backdoors to a compromised system.

The Trojan is even smart and can detect what browser is being used via the user agent and customize the exploit based on the browser settings.

Here is the ad, which was translated into English by Websense:

Dear Friends! We would like to offer you multi-component exploit Web-Attacker IE604, that realizes vulnerabilities in the internet browsers Internet Explorer and Mozilla Firefox. With the help of this exploit you will be able to install any programs on the local disks of visitors of your web pages. In the foundation of work of the exploit Web-Attacker IE0604, there are 7 already-known vulnerabilities in the internet browsers: Objective of the Exploit: Hidden drop of the executable from the deleted source to the local hard drive of the site visitor.

-Bypasses all security measures-Is not blocked by Firewalls [Agnitum Outpost, Zone Alarm, Sygate Personal Firewall]

-Tri-level protection -Flexible installation -Updates -Detailed Statistics

For the full alert, with screenshots, click here.

John Leyden of the Register is also covering this story.

trimMail's E-Mail Battles has an interesting story about why some of these kits are so dangerous. Here is an excerpt:

Smart computer users know that once a computer is infected by a rootkit, it's changed forever. And as Windows rootkits go, Hacker Defender is among the most dangerous. The author of Hacker Defender, holy_father, explains why he does what he does, and what you can do to detect his rootkit.

Antivirus companies sell a fake sense of security, but they do not bring real security to your computer. Antivirus just fights programs that are visible to common users. They don't care about the cause.

Do it yourself kits are becoming increasingly common and are making the Internet increasingly dangerous for the common user.

Here is a recent post, I wrote about "how to scam kits" and one that is designed for use in committing fraud on eBay.

Link, here.