Showing posts with label cyber criminals. Show all posts
Showing posts with label cyber criminals. Show all posts

Monday, January 4, 2010

El Malware y su futuro en el 2010


Según wikipedia el “Malware es un software que tiene como objetivo infiltrarse en el sistema y dañar la computadora sin el conocimiento de su dueño, con finalidades muy diversas…”
Un ejemplo de malware son los troyanos (esos programitas que parecen inofensivos pero le dan acceso remoto a una persona sin nuestro consentimiento), los virus ya conocidos por todos, etc.

Desde que la banca coloco sus sistemas al público mediante internet para darle la facilidad al usuario final, de que realice sus operaciones sin trasladarse físicamente a una sucursal, los delincuentes tuvieron que evolucionar, atacar ese campo que estaba naciendo y que no había sido tocado por ellos, el ataque más conocido por la población hoy en día es el Phishing. Pero hay una modalidad de malware que va contra el sector bancario online y es el Crimeware. El desarrollo de este tipo de software es muy lucrativo para los programadores o blackhats que se especializan en esta modalidad, este tipo de software se aprovecha de vulnerabilidades de sistemas operativos o vulnerabilidades en programas instalados para infectar al usuario.

Herramientas como: Liberty Exploit System, Neon Exploit System, Sploit25, Unique Sploits Pack, Eleonore Exploits Pack, YES Exploit System, etc., pueden ir desde 500$US hasta 3000$US. Esta cantidad de dinero por el desarrollo de malware hace que los programadores saquen provecho por la venta de estos sistemas y hasta den garantías a sus compradores sobre si su sistema es detectado por algún antivirus.

Dependiendo del tipo de malware y lo complejo que sea varia su precio, encontraran ofertas en internet de troyanos por 250$US hasta los sistemas de crimeware mencionado anteriormente. Rusia lleva la delantera y le sigue china en el desarrollo de malware. Los nuevos estudios de Mcafee Labs pronostican que en el 2010 la compañía que será más atacada por este tipo de malware va a ser Adobe y se dejara de lado a Microsoft Office, debido a que se van encontrando nuevas vulnerabilidades en sus programas lideres como Adobe Reader y Adobe Flash. Solamente con abrir un sencillo PDF realizado por estos sistemas y una versión vulnerable de Adobe Reader el usuario sin darse cuenta se descarga un malware, se infecta y ya pasa a ser una víctima más en el mundo de los ciber-delitos, lo mismo pasaría con una animación Flash.

Más allá, la Cyber-Warfare también puede ir por este rumbo y cualquier país involucrado utilizaría estos sistemas para en vez de ir contra lo monetario atacar los sistemas informáticos gubernamentales de su contraparte mediante estas botnets.
Adobe constantemente está en la corrección de estas vulnerabilidades y han desarrollado un blog para este tipo de temas, claro está que si como usuarios no ponemos de nuestra parte y no mantenemos los sistemas actualizados, no será nada útil las correcciones que se hagan a nivel de desarrollo de código hasta que instalemos los updates necesarios.

Para más info sobre adobe y su blog: http://blogs.adobe.com/psirt/

Sunday, September 13, 2009

Russian Cyberspace: A daylight in the dark world

Due to rapid increase in number of internet users and technology, the magnitude of threat-ratio is also multiplying every year. Cyber crime in today's fast moving world is considered as a potential business. FBI recorded and reported a loss of $265 million during the annual year of 2008. However, these does not cover other billions USD loss counted towards other parts of the world. Due to unfair nature of national and international cyber law enforcement structure and joint efforts of overseas government may result in serious problems between two or more countries.


Loss reported always become a part of "strategic revenue recovery plan" for the organizations by imposing higher prices on current products or by increasing the service charges for new or existing customers. Today's cyber crime is highly organized, transitional and very secretive with major criminal groups operating from more than 30 countries. The trend of cybercrime has emerged during the late 1990s to early 2000s in eastern Europe (i.e Republic of Soviet Union and other countries). Due to the presence of injustice and lack of law and order, the highly educated and technologically powered segments of population in Russia conduct sophisticated criminal activities to make their living. Apart from financial motivation, these criminals successfully suppress ethical anxiety and fear of stealing someone else entire life savings
by hiding their identity and forwarding the national justifications.

Statements like:
"They deserve what they are getting after what they've done to us"
"We are taking back what's rightfully ours"
are really common in online forums based in Eastern Europe. The highlights of which can be seen below:

In October 2004, FBI run a joint operation with Secret Service and USPIS called "Operation Firewall" which resulted in several arrests and termination of online criminal portals, "ShadowCrew" and "CarderPlanet". Other successful operations have also come forward, such as "Operation Cardkeeper" and "DarkMarket" in 2006 targeting the US and Western European criminals, concluded in October 2008 with 60 consecutive arrests. This fear has brought significant changes to the underground community such that many have left this illegal business and took their careers in different directions and those who remain intact gone underground.

Friday, March 20, 2009

Hackers inside the ATMs: A red alert to world's major financial institutions


When talking about electronic disobedience, many different aspects come forward to point the criminal activities launched using electronic media (computers and internet). Apart from those of money laundering and vandalism issues one is considered to be the most intenseful fraud, "credit card fraud" or "e-fraud". As from the years of data breaches and theft reports, such as:

"11 Mar 2009 - Computerweekly.com: Data theft Trojans fastest growing cyber threat"
http://www.computerweekly.com/Articles/2009/03/11/235229/data-theft-trojans-fastest-growing-cyber-threat-says.htm

"The ITC 2008 Reports: Data Theft/Data Breaches - by industry/cause"
http://idtheftmostwanted.org/ITRC Breach Report 2008.pdf

It has been proved that the underground criminal market is growing fast and find new ways to remain undetectable in almost every first attempts. These changes of development can be noticeable from 2002-2009, an enormous increase in data theft pushed at various firms in the world. Cracking the ATMs is not new, but quite far changing the shape of existing attack in new ways.

Recently there was a news published at DarkReading.com, in which it has been stated clearly about how cyber criminals are moving and driving their thirst of money by passing any sort of security infrastructure to accomplish their goals. From time to time these criminals are changing and adobting new methods, for instance, a creation of normal phishing attack using DIY toolkits driven more towards serving the automated information-stealing malware today.

Sophos recently revealed a latest hack which affects the Diebold based ATM machines:
http://www.sophos.com/blogs/gc/g/2009/03/18/details-diebold-atm-trojan-horse-case/

Although, Diebold has published the security update in late January for their Windows-based Opteva platform. A trojan identified gave complete access to the criminal. One thing to notice that how far today's high-tech criminals have moved a step forward to understand the internal functions and API calls of the cash machines. This has not only to deal with virtual access of ATM but also a physical access (or internal access) to install the malware. The trojan was silently collecting PINs (aka. Track2 information) from the magnetic strips which further allows an attacker to clone real cards.

Looking at other perspectives where the recent incident in Europe "Several Checkout card readers in major supermarket chains", a news reported by Sophos in which the card readers were tampered with built-in sniffers. Among the known victims were Wal-Mart and Asda chains. These all aspects give a clear high-lights on how the cyber criminals of past moving faster in finding their ways to inject new ideas to steal the financial records.