Phishing
Phishing

Phishers using smarter hooks

Fraud attempts grow with Trojans, keystroke loggers and stolen screenshots

Iain Thomson

Groups attempting to trick internet users into revealing bank account details and other sensitive information are stepping up their efforts.

According to figures from internet firm MessageLabs, the number of phishing emails it has encountered has increased from 279 in September 2003 to 337,050 in January 2004.

Advertisement

Other phishing groups are also using new techniques to defeat technical measures put in place to foil their scams.

Some infect a host PC with a Trojan and use keystroke loggers to steal passwords for later use.

To combat this, banks have introduced innovative designs on their websites that allow users to pull down menus to enter passwords rather than key them in directly.

But now Australian anti-spam group Code Fish has discovered a new Trojan that attempts to steal passwords by stealing screenshots rather than keystrokes.

Users are sent what looks like an invoice for the purchase of a website. But a VBScript Trojan, svchostss.exe, is automatically downloaded if they check out the site that the email claims they have bought.

This Trojan then attempts to take screen grabs from the PC whenever it is used to access financial sites, including that of Barclays Bank.

Barclays said in a statement: "As you would expect, we closely monitor changes and developments in this space and work closely with other banks and the Hi-Tech Crime Unit.

"We also guarantee to customers that they will not bear any financial loss as a result of fraud against them.

"We are encouraging them to regularly update their antivirus protection software/firewall software and never to reveal their complete ID/password information. Also simply to delete any suspicious emails without opening them."

David Linford, director of anti-spam organisation SpamHaus, said better cooperation between law enforcement agencies could end phishing.

"What the spammers don't realise [is] that they aren't really anonymous - noone is on the internet.

"If law and order wanted to stop this they could if they started talking to each other - cooperation between forces is missing. Most of these [attacks] are coming form Poland and Russia and with international cooperation these computers could be seized."

The UK National Hi-Tech Crime Unit said it is working with colleagues abroad. A spokeswoman told vnunet.com: "We're currently working with overseas forces but have to be at the behest of their jurisdictional systems.

"Naturally we can't comment on ongoing investigations but phishing is being looked at."

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Online risks

Know the risks of online business

As the bad guys get smarter, what can you do? James Watson and Emma Nash find out

US falls hook, line & sinker for phishing

Estimated 1.8 million US adults conned out of $1.2bn last year

Police net 12 phishing suspects

Eastern Europeans under arrest as Hi-Tech Crime Unit swoops on addresses in London and Kent

NHTCU wipes Smile off phisher's face

Hi-Tech Crime Unit arrests Lancashire man over alleged phishing attack on internet bank users

Related whitepapers

Related jobs

Most watched

eu flag

V3.co.uk weekly debrief, 6 Nov 09

This week, Europe decides what to do with illegal file sharers

Intel unveils its micro server platform

Small-enclosure systems take aim at hosting market

Analysis and Reports

Remote access - Three steps to getting connected

3.4 million UK professionals now work from home – is your company equipped?

Cost benefits of a global collaboration network

This white paper is a must read for organisations looking for evidence of the bottom-line benefits of high-definition video and voice communications

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

shackleton

Content management tools "barely being used"

Open Text chief predicts more consolidation in ECM market

Scott Totzke

Interview: Scott Totzke, VP global security, RIM

We ask the BlackBerry maker's head of security what CIOs...

Apple Magic Mouse

Review: Apple Magic Mouse

Multi-touch makes an appearance on Apple's latest mouse

clouds

Industry needs to come clean on cloud security

Trend Micro CTO warns of widespread data theft

Primary Navigation