Bank Accounts Vulnerable For Victims of ZeuS Trojan Variant 'Gameover'
tsu doh nimh writes "Organized crooks have begun launching debilitating cyber attacks against banks and their customers as part of a smoke screen to prevent victims from noticing simultaneous high-dollar cyber heists, the FBI is warning. The thefts, aided by a custom variant of the ZeuS Trojan called 'Gameover,' are followed by distributed denial of service (DDoS) attacks against banks and the victim customers. The feds say the perpetrators also are wiring some of the money from victim organizations directly to high-end jewelry stores, and then sending money mules to pick up the pricey items."
I keep all my money in my house! Perfectly safe. No organized crooks gonna steal my money.
"None can love freedom heartily, but good men; the rest love not freedom, but license." --John Milton
Seriously? People are /still/ clicking the links in shady emails/downloading files from them? What, is this 1998?
wiring some of the money from victim organizations directly to high-end jewelry stores, and then sending money mules to pick up the pricey items
There, aiding and abetting cyber crime. Time that ICE officials seize these 'storefronts' and close them down!
Could this be related to the recent news about Anonymous?
Have fun trying to pull more than 10 bucks out of that credit card.
*sigh* debt sucks.
Gameover, man! Gameover!
Why is it that every time I see a 'security' oriented blog, it is running on Wordpress?
We just need to get everyone to use M$ antivirus, M$ antispyware, M$ IExplorer and everyone needs to run Winblows. That should prevent this sort of thing.
didnt we just have an article about anonymous threatening banks?
What is the world coming to nowadays? Why are these crooks looking for holes in the computer servers and steal money? Why can't they steal the money honestly by buying the congress critters and passing legislation that forks over 7.1 trillion dollars? When will these crooks realize the Return on Investment for putting money in campaign contribution is like one million percent. These American Congresscritters are the best money can buy. Instead they go hire script kiddies and money mules. People like these give a bad name to the legitimate thieves of Wall Street.
sed -e 's/Chuck Norris/Rajnikant/g' joke > fact
The foreign crooks are doing exactly what our local crooks did, just further back on the timeline. First they got a lot of money from prohibition, then they broke into the big time money of politics. The key point is you can't take short cuts on the road to evil wealth and power, you've got to achieve all the sub-quests along the way before you get to fight the final boss. You don't get to bribe the federal gov without large bags of money and knowing the right people to pay off.
For when you really need to dress something up as dangerous, the type of thing that would star a team of, perhaps, eleven big-name actors and a casino.
Yet Another Tech Blog
(but so much more, including game and movie reviews)
http://yanteb.peasantoid.org
and my daughters use her computer. I have little doubt it has been hacked as I've had to re-image it several times. I can not convince my wife to use a live CD for online banking. I guess it will take us getting wiped out to drive home this point. There is an inflection point between prudence and convenience. Woman are especially non prudent (I want to access my bank when I need it, I am not going to reboot) This is a larger problem of identity that needs solving. It is big bucks now. We need a secure solution. As as a professional coder, I do not see one. Anything on the net can be hacked. Voting machines? On the net, consider the election stolen. Heck, just electronic voting, consider the election stolen. Nothing electronic is immune and all of it is vulnerable. Stinks, but that is reality.
So much for your obscure security... you just put out a press release for the whole world. You couldn't have done worse if you'd painted big bullseyes on your garage and roof - don't wanna exclude yourself from satellite view - with a red $ sign where the dot should be. *snicker*
I can hear the booo and hisses already, but this is a large reason why I fucking hate Windows. Let's be real here, everyone getting hacked by these knuckleheads are idiots themselves (to a degree) AND running windows. But what about this: I just imaged and updated my Windows 7 64 system, only use Firefox, and have Microsoft AV (free) enabled. I was minding my own business surfing the web in what I thought was a fairly secure setup, some random popup or link injected code through what I believe was a flash vulnerability (again the box was only a month old) and installed some fucked up rootkit that MS AV actually found the next day. WTF? 0-day exploits CRUSH windows, despite the UAV etc, some how this shit still gets through. Yes, I could have done probably xyz things to protect myself, which I would believe if I were running XP, but this is a 1Mo old version of 7, automatic updates, and I only use firefox. FML.
Web browsers should run in a VM session that is incompatible with the host operating system on a binary level. This kind of aformentioned horseshit rarely if ever happens to everyday average normal guys just browsing the web on their Macs or Ubuntu boxes. Also, fuck it, I'm only browsing the web on a Linux image from now on on this Windows box (and just for reference the box is only used for gaming, occasionally slashdot raging)
Hello, those cybercriminals are stupid. Defrauding jewellery merchants is highly detrimental to one’s health. Jewellers and dimanond merchants are 95% jewish families. They pick up the red telephone and Mossad comes hunting down the perpetrators, let there be no doubt about that!
Jews learned the hard way during 1933-1945 that they cannot let goyim people take away jewish wealth and jewish lives with impunity and they are now firmly on the opinion that Masada must not fall again!
Mossad was able to remotely blew up secret and massively guarded iranian military sites and with ease, so guess how much it is easier for them to blow up or poison or simply shoot those rogue hackers messing with the Jew-ellery business. They will put the heads on display to deter further e-attacks.
They created something truly devious in the game over trojan. We all just lost.
I8-D
This is a nasty infection and can cause significant damage. From what I have read, Zeus can attack both users who are local admins and those that are non-admins. The difference is that the attack of non-admins is only for that user, where if the user is a local admin, every user is infected! To reduce the attack surface and reduce the overall effectiveness of Zeus, you should make all users non-admins! Software to help with that is PowerBroker Windows Desktops (www.beyondtrust.com), which runs on Windows XP, Vista, and 7, as well as server OSs by microsoft. This software can ensure that users can run all of their required apps, even if they require local admin privileges. Removing the user from being a local admin can also stop the effectiveness of over 95% of all other malicious apps that might attack the computer, according to Microsoft.
Derek Melber, MVP
What is your major malfunction?
--
BMO
That actively tracks ALL zeus C&C servers https://zeustracker.abuse.ch/monitor.php?filter=all & then "security-hardening" your Windows setup via CIS Tool & more (yes, they now have a Vista/Win7/Server2008 capable model of it) via this guide does the rest:
http://www.google.com/search?sclient=psy-ab&hl=en&site=&source=hp&q=%22HOW+TO+SECURE+Windows+2000/XP%22&btnG=Search&gbv=1&sei=YU_cTsPxFOrc0QGMhMiKDg
It's been WELL rated on this website (of ALL places, considering it's so "Pro-*NIX" here)
* THE APK SECURITY GUIDE GROUP 10++ THUSFAR (from +5 -> +1 RATINGS, usually "informative" or "interesting" etc./et al):
APK SECURITY GUIDE:2005 -> http://developers.slashdot.org/comments.pl?sid=167071&cid=13931198
APK SECURITY GUIDE:2009 -> http://it.slashdot.org/comments.pl?sid=1361585&cid=29360367
APK SECURITY GUIDE:2009 -> http://yro.slashdot.org/comments.pl?sid=1218837&cid=27787281
APK SECURITY GUIDE:2008 -> http://ask.slashdot.org/comments.pl?sid=970939&cid=25093275
APK SECURITY GUIDE:2010 -> http://tech.slashdot.org/comments.pl?sid=1885890&cid=34358316
APK SECURITY GUIDE (old one):2005 -> http://it.slashdot.org/comments.pl?sid=154868&cid=12988150
APK SECURITY GUIDE:2008 -> http://ask.slashdot.org/comments.pl?sid=970939&threshold=-1&commentsort=0&mode=thread&no_d2=1&cid=25092677
APK SECURITY GUIDE:2008 -> http://tech.slashdot.org/comments.pl?sid=1027095&cid=25747655
APK SECURITY TEST CHALLENGE LINUX vs. WINDOWS:2007 -> http://it.slashdot.org/comments.pl?sid=267599&threshold=1&commentsort=0&mode=thread&cid=20203061
* Yes, that guide's points implementation To "immunize" a Windows system, I effectively use the principles in "layered security" possibles!
http://www.bing.com/search?q=%22HOW+TO+SECURE+Windows+2000%2FXP%22&go=&form=QBRE
I.E./E.G.-> I have done so since 1997-1998 with the most viewed, highly rated guide online for Windows security there really is which came from the fact I also created the 1st guide for securing Windows, highly rated @ NEOWIN (as far back as 1998-2001) here:
http://www.neowin.net/news/apk-a-to-z-internet-speedup--security-text
& from as far back as 1997 -> http://web.archive.org/web/20020205091023/www.ntcompatible.com/article1.shtml which Neowin above picked up on & rated very highly.
That has evolved more currently, into the MOST viewed & highly rated one there is for years now since 2008 online in the 1st URL link above...
Which has well over 500,000++ views
"To reduce the attack surface and reduce the overall effectiveness of Zeus, you should make all users non-admins! Software to help with that is PowerBroker Windows Desktops (www.beyondtrust.com), which runs on Windows XP, Vista, and 7, as well as server OSs by microsoft. This software can ensure that users can run all of their required apps, even if they require local admin privileges. Removing the user from being a local admin can also stop the effectiveness of over 95% of all other malicious apps that might attack the computer, according to Microsoft." - by derekmelber (2523158) on Friday December 02, @10:47AM (#38238032)
You don't need a custom software to do that though. Gpedit.msc has options that make even a local admin on a system HAVE TO DO THE SAME STUFF a typical end user has to (& more, more "stringently" no less, for all users).
E.G.=> It "enhances" UAC even, by making even admin class users have to "validate themselves" vs. bogus installers & have to "logon" to perform an installation (by logon, I mean sign in your ADMIN level username + password, whereas usually UAC only makes you click a button warning you that you need admin privleges). In fact? It even makes it even MORE STRINGENT than Linux has it setup using sudo by default...
So, anyhow/anyways: The settings to examine & change are as follows in gpedit.msc &/or regedit.exe:
---
Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\User Account Control: Admin Approval Mode for the Built-in Administrator account
OR
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System /v FilterAdministratorToken
(Set as ENABLED)
---
Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode
OR
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System /v ConsentPromptBehaviorAdmin
(Set as PROMPT FOR CREDENTIALS)
---
Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\User Account Control: Behavior of the elevation prompt for standard users
OR
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System /v ConsentPromptBehaviorUser
(Set as Automatically deny elevation requests)
---
Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\User Account Control: Detect application installations and prompt for elevation
OR
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System /v EnableInstallerDetection
(Set as ENABLED)
---
Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\User Account Control: Only elevate UIAccess applications that are installed in secure locations
OR
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System /v EnableSecureUIAPaths
(Set as ENABLED)
---
Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\User Account Control: Run all administrators in Admin Approval Mode
OR
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA
(Set as ENABLED)
---
Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\User Account Control: Switch to the secure desktop when prompting for elevation
OR
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System /v PromptOnSecureDesktop
(Set as ENABLED)
---
Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\User Account Control: Virtualize file and registry write failures to per-user locations
OR
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies