01 Oct 2009
A recent phishing and malware scam netted a group of criminals some €300,000 in stolen funds, according to experts.
Security vendor Finjan said that the criminals used a piece of financial malware to infect users and steal account details without being caught by bank security systems.
The attackers used a combination of phishing sites and exploit attacks to dupe users into downloading a piece of malware known as Zeus.
Once installed, the Trojan covertly dialled into a command server operated by the group. The server then directed the Trojan to gather account details and transfer funds to a third-party account and create a forged bank statement.
As a result of the campaign, Finjan estimated that the cyber criminals were able to steal roughly €300,000 in just 22 days.
"In this case, the specific criteria that the Trojan received from its command and control centre mark a whole new level of sophistication in the techniques used by cyber criminals," said Finjan chief technology officer Yuval Ben-Itzhak.
"Using these methods they successfully evaded anti-fraud systems that banks deploy. We dubbed it the Anti anti-fraud."
Further complicating matters was the use of third-party 'money mules' to launder the stolen funds and make the criminals behind the operation harder to track down.
The mules are often hired on the promise of a legitimate 'work from home' job and are unaware of the fraudulent activity. They accept transfers from the compromised accounts and then send the money back to the criminals as a wire transfer.
Latest stories from Web
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Hands on with the highly anticipated Android 4.0 Ice Cream Sandwich hybrid tablet
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
Low Latency Network Engineer, Senior Network Engineer...
SQL DBA - (North London) North London , £45k - 50k...
Business Architect – (North London) £65,000 – 75,000k...
Graduate Software Engineer - Javascript OR Android...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?