Bank Accounts Vulnerable For Victims of ZeuS Trojan Variant 'Gameover'
tsu doh nimh writes "Organized crooks have begun launching debilitating cyber attacks against banks and their customers as part of a smoke screen to prevent victims from noticing simultaneous high-dollar cyber heists, the FBI is warning. The thefts, aided by a custom variant of the ZeuS Trojan called 'Gameover,' are followed by distributed denial of service (DDoS) attacks against banks and the victim customers. The feds say the perpetrators also are wiring some of the money from victim organizations directly to high-end jewelry stores, and then sending money mules to pick up the pricey items."
I keep all my money in my house! Perfectly safe. No organized crooks gonna steal my money.
"None can love freedom heartily, but good men; the rest love not freedom, but license." --John Milton
Seriously? People are /still/ clicking the links in shady emails/downloading files from them? What, is this 1998?
Could this be related to the recent news about Anonymous?
Why is it that every time I see a 'security' oriented blog, it is running on Wordpress?
didnt we just have an article about anonymous threatening banks?
What is the world coming to nowadays? Why are these crooks looking for holes in the computer servers and steal money? Why can't they steal the money honestly by buying the congress critters and passing legislation that forks over 7.1 trillion dollars? When will these crooks realize the Return on Investment for putting money in campaign contribution is like one million percent. These American Congresscritters are the best money can buy. Instead they go hire script kiddies and money mules. People like these give a bad name to the legitimate thieves of Wall Street.
sed -e 's/Chuck Norris/Rajnikant/g' joke > fact
The foreign crooks are doing exactly what our local crooks did, just further back on the timeline. First they got a lot of money from prohibition, then they broke into the big time money of politics. The key point is you can't take short cuts on the road to evil wealth and power, you've got to achieve all the sub-quests along the way before you get to fight the final boss. You don't get to bribe the federal gov without large bags of money and knowing the right people to pay off.
For when you really need to dress something up as dangerous, the type of thing that would star a team of, perhaps, eleven big-name actors and a casino.
Yet Another Tech Blog
(but so much more, including game and movie reviews)
http://yanteb.peasantoid.org
and my daughters use her computer. I have little doubt it has been hacked as I've had to re-image it several times. I can not convince my wife to use a live CD for online banking. I guess it will take us getting wiped out to drive home this point. There is an inflection point between prudence and convenience. Woman are especially non prudent (I want to access my bank when I need it, I am not going to reboot) This is a larger problem of identity that needs solving. It is big bucks now. We need a secure solution. As as a professional coder, I do not see one. Anything on the net can be hacked. Voting machines? On the net, consider the election stolen. Heck, just electronic voting, consider the election stolen. Nothing electronic is immune and all of it is vulnerable. Stinks, but that is reality.
So much for your obscure security... you just put out a press release for the whole world. You couldn't have done worse if you'd painted big bullseyes on your garage and roof - don't wanna exclude yourself from satellite view - with a red $ sign where the dot should be. *snicker*
You and I might see their behavior as hypocritical and double-standardish, but they don't. I doubt we have a pin sharp enough to burst their bubble.
I can hear the booo and hisses already, but this is a large reason why I fucking hate Windows. Let's be real here, everyone getting hacked by these knuckleheads are idiots themselves (to a degree) AND running windows. But what about this: I just imaged and updated my Windows 7 64 system, only use Firefox, and have Microsoft AV (free) enabled. I was minding my own business surfing the web in what I thought was a fairly secure setup, some random popup or link injected code through what I believe was a flash vulnerability (again the box was only a month old) and installed some fucked up rootkit that MS AV actually found the next day. WTF? 0-day exploits CRUSH windows, despite the UAV etc, some how this shit still gets through. Yes, I could have done probably xyz things to protect myself, which I would believe if I were running XP, but this is a 1Mo old version of 7, automatic updates, and I only use firefox. FML.
Web browsers should run in a VM session that is incompatible with the host operating system on a binary level. This kind of aformentioned horseshit rarely if ever happens to everyday average normal guys just browsing the web on their Macs or Ubuntu boxes. Also, fuck it, I'm only browsing the web on a Linux image from now on on this Windows box (and just for reference the box is only used for gaming, occasionally slashdot raging)
They created something truly devious in the game over trojan. We all just lost.
I8-D
This is a nasty infection and can cause significant damage. From what I have read, Zeus can attack both users who are local admins and those that are non-admins. The difference is that the attack of non-admins is only for that user, where if the user is a local admin, every user is infected! To reduce the attack surface and reduce the overall effectiveness of Zeus, you should make all users non-admins! Software to help with that is PowerBroker Windows Desktops (www.beyondtrust.com), which runs on Windows XP, Vista, and 7, as well as server OSs by microsoft. This software can ensure that users can run all of their required apps, even if they require local admin privileges. Removing the user from being a local admin can also stop the effectiveness of over 95% of all other malicious apps that might attack the computer, according to Microsoft.
Derek Melber, MVP
What is your major malfunction?
--
BMO