Google Search

Showing posts with label crooks. Show all posts
Showing posts with label crooks. Show all posts

Thursday, April 18, 2013

Point-of-Sale malware attacks – crooks expand their reach, no business too small

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Filed Under: Featured, Malware

Numaan Huq and Richard Wang of SophosLabs have been keeping track of the evolution of Point-of-Sale malware.

We've recently been tracking a set of incidents involving malware attacking Point-of-Sale (PoS) equipment.

Your personally identifiable information (PII) flows into PoS devices, across PoS networks, and is processed by PoS servers, every time you pay for things without using cash.

As a result, PoS equipment and the local-area networks to support it are found all over the world, in both developed and developing countries.

When was the last time you tried to pay for a hotel stay in cash, for example?

Even if you settled the bill with cash, you probably swiped or waved a payment card when you checked in, just to avoid having to lay down a large cash deposit.

As a result, PoS systems are a lucrative target for crooks.

So it's not surprising that we've written about this particular malware family, Troj/Trackr-Gen, and its thirst for credit card data before.

It seems the criminals behind it have added a few new tricks in the last 15 months.

The most interesting development is that some versions now include the ability to exfiltrate data directly rather than just dumping it to disk.

? The Payment Card Industry has a set of Data Security Standards, known unsurprisingly as PCI-DSS. The standards specify, amongst other things, that credit card data must in general be encrypted if it is stored, and that some data, such as CVV numbers, mustn't be stored at all once a transaction is complete. Ironically, the crooks have learned from this, and are avoiding reading from or writing to disk themselves.

Another change is found when examining some of the targets.

As before, the criminals are avoiding very large businesses but in addition to the commonly attacked hospitality industry and hotel targets there are smaller victims, including a single car dealership in Australia.

A couple of cosmetic changes have also been made.

There is a new generator for random filenames, creating completely random five-character names such as IXWIG.exe and KPAOE.exe.

For variants using hardcoded names the common use of rdasrv.exe has been extended to include filename options designed to hide in plain sight such as windowsfirewall.exe or msupdate.exe.

It seems that no victim is too small for Point-of-Sale malware.

The popularity of terms like "Advanced Persistent Threat" and "state-level malware actors" may make it sound as though only the biggest multinationals and parastatals are at risk these days.

But stealing $75 each from 1,000,000 people gives the same financial result as stealing $75 million from a megacorporation.

So you simply cannot assume that your business or organization is not a big enough target to worry about web attacks or targeted malware.

Remember this: there is no radar below which you can fly.

As a final thought, since we already know the how and the why of this latest round of PoS attacks, we invite you to consider the where.

There's an intriguing hint buried in the code:

We don't know if that's where the crooks are from, or if it's where they've been most successful in infiltrating PoS networks (Botswana, home to the astonishing inland Okavango Delta, has a strong hospitality industry), or perhaps just where they spent some of their ill-gotten gains on a vacation.

Do you run a small business that relies on PoS equipment?

If so, how much of a challenge are you finding it to stay ahead of crooks like this?

Have your say in the comments...

Follow @sophoslabs

Image of PoS machine courtesy of Shutterstock.


View the original article here

Friday, March 15, 2013

Anatomy of a phish - how crooks hack legitimate websites to steal your details

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Old-school phishing is where cybercrooks lure you into logging in to your bank account on one of their websites.

When you enter your personally identifiable information (PII), as you would on the bank's real site, it gets uploaded to the crooks instead of to your bank.

The idea, of course, is that they then use the credentials they just stole to start draining your account.

So phishing is still worthwhile to the crooks, even though it doesn't seem to be quite as successful as it used to be. Many of us have learned to take great care when we're banking online, and to check for the "vital signs" of a scam before we trust a website with our usernames and passwords.

Nevertheless, the phishers are still giving it all they've got. By combining simplicity with accuracy, they're creating banking scams that are much more believable than the crude and misspelled emails and websites that were common a few years ago.

If you pick your moment, or just get lucky, there's still money to be made.

In Australia, for example, today (at least in Sydney) has been a very wet and gloomy public holiday.

Just the sort of morning to loaf on the couch with your laptop or your iPad and goof off online, where you might have received an email like this one:

Many banks now have a closed cloud-style email service built into their internet banking sites. The idea is that you'll get into the habit of logging in securely to read important messages, rather than believing what arrives in insecure emails.

The bank still sends you emails, but they don't contain any detail - they just give you an overview (e.g. "your statement is ready"), and advise you to read the full message on the secure site. A bit like the message here, in fact.

But what your bank won't do is to invite you to click a link to get to the secure site. They rightly leave you (indeed, they urge you) to find your own way to the banking portal, so you're not at the mercy of the URL embedded in the email.

So the link here is certainly phishy - it shouldn't be present at all - but it doesn't look like the sort of obvious phishing nonsense you often see.

You probably know what I mean: weird and unlikely domains such as really.your.bank.wefljdrsecxr.example.org that are an instant giveaway of bogosity.

In fact, this phish links to a government website in .cn (that the People's Republic of China, or PRC):

The government site seems to have had a security lapse, allowing the crooks to add a small and simple web page called nabau.html.

This page silently redirects your browser elsewhere by using this HTML:

The redirect takes you off to another hacked site, specified in the URL as an IP number rather than as a domain name.

This presents you with a bogus login page hosted on a web server (it looks like part of the Computer Science department) at a Colombian university:

Ironically, this bogus page helpfully advises you to keep up to date with anti-virus, firewall software and the latest patches, and urges you to report phishing scams to NAB.

When you click Login to submit the form, the POST request (HTTP's name for an upload) goes to yet another hacked web property. This one is a student vacation site in the USA, apparently with some insecure plugins in its blogging subdirectories.

You never get to see the site's main page, which is unexceptional:

Instead, the web upload that is linked to from from the Colombian university page gives the crooks their first page of login data.

Then you're shuffled back to the server in Colombia to face a request for another page of PII:

The POST request on this page uploads your formful of data to the same place as before: the US student vacation site.

This time, the vacation site bounces you back to Australia, rounding off the phishers' journey.

You end up unremarkably on National Australia Bank's own site, albeit that you're on the regular main page, not amongst the internet banking pages:

Let me be quick to say that you ought not to fall for this sort of phish:

NAB wouldn't have put a link in the email, so you ought not to have clicked it.None of the so-called banking sites referenced a nab.com.au URL.None of them used secure HTTP, also known as HTTPS.

(HTTPS is the protocol that puts a tiny padlock in the address bar at the top of your browser's screen.)

Nevertheless, this phish didn't take you to any sites that would have stood out, under normal circumstances, as part of the cybercriminal underworld.

It relied on three unremarkable and legitimate servers, owned by legitimate organisations and operated by unsuspecting sysadmins, in three different countries: PRC, Colombia and the USA.

That's why even self-proclaimed "safe surfers" - people who back themselves not to wander off into obviously-shady parts of the web - should consider themselves at risk.

Be careful out there. And that applies whether you're browsing or running an online business.

The crooks want to redirect your browser into harm's way, and they want to use your servers to help them do so.

Follow @duckblog

Running a web server at home?

Why not try out the free Sophos UTM Home Edition?

You get web and email filtering, web application firewall, IPS, VPN and more for up to 50 IP addresses. You can also protect up to 12 Windows PCs on your network with Sophos Anti-Virus!

(Note: registration required.)


View the original article here