Wanted: Hackers For Large-Scale Attacks On American Banks
Trailrunner7 writes "RSA's FraudAction research team has been monitoring underground chatter and has put together various clues to deduce that a cybercrime gang is actively recruiting up to 100 botmasters to participate in a complicated man-in-the-middle hijacking scam using a variant of the proprietary Gozi Trojan. This is the first time a private cybercrime organization has recruited outsiders to participate in a financially motivated attack, said Mor Ahuvia, cybercrime communications specialist for RSA FraudAction. The attackers are promising their recruits a cut of the profits, and are requiring an initial investment in hardware and training in how to deploy the Gozi Prinimalka Trojan, Ahuvia added. Also, the gang will only share executable files with their partners, and will not give up the Trojan's compilers, keeping the recruits dependent on the gang for updates."
The attackers are promising their recruits a cut of the profits, and are requiring an initial investment in hardware and training
as any confidence man could tell you, the best marks are those that think they are in on the scam...
At least that's what I would do. Hire the best crackers myself, and then send them to be hired there.
Won't give up their "compilers" now will they.. Bastards, I'll drop in my version of GCC and show them! Er, ahem, I think the article means "source code." And even with that a determined reverse-engineering effort could negate that too..
Can I apply right now?
1. sit on your ass
2. mine bitcoins
3. USD-based banks are DESTROYED! lol.
I heard that's how it works, lol.
Also, the gang will only share executable files with their partners
I want those executables, give them to me now so I can run them immediately! Hell yes, they are gonna own, gimme gimme gimme. Also let me root my phone and get free clones of apps that cost a dollar, this is all good things for my bank account!
Why bother recruiting people if you can just hire bots, or herd your own? Why go for 100 small ones if just a few bigger ones will yield you the same number of victims?
These seem like either very inexperienced criminals, or indeed, as someone else suggested, scammers that want to rip off botnet herders, not banks. You don't involve people in your gang if you don't absolutely need them. You don't train them, unless you absolutely need them to know things. The less people know as little as possible, the smaller the chance you will get caught. Causing a racket by recruiting up to 100 herders does not fit that MO.
I was promised a flying car. Where is my flying car?
I'm trying to remember, who are the bad guys here, the law-breaking, savings-stealing douchebags, or the guys running the botnet?
They should be hacking banks using OPEN SOURCE SOFTWARE and tools. (Strokes beard thoughtfully.) The use of proprietary, closed-source tools takes away from the common, computer using felon the ability to maintain his own malicious code.
~ Richard Stallman
May God the merciful grant you peace. You will be surprised to hear from me. I am MRS. HELENA SHOSTAKOVICH, widow of the late DMITRI SHOSTAKOVICH of hacker fame. My dear husband past away two weeks ago, leaving behind 1,500,000 credit card numbers worth THREE HUNDRED MILLIONS US DOLLARS. As I am unable to realize this sum here in Russia, I have been authorized to advance into your bank account FIVE MILLION DOLLARS for assistance in retrieving this funds. The requirement from you, to show you are an honest man of principle and good faith, is an insignificant small purchase of hardware from the following list: ...
To avoid Putin's spies, I have retained agents in NIGERIA who will handle your transactions. Forward your credit card particulars to:
Mr. JOHN MBUTU
POST OFFICE WILL CALL
LAGOS, NIGERIA
#DeleteChrome
these guys must be morons if they think that they can keep 100 people quiet about anything
Timothy Olyphant's character worked that out with his scheme in Die Hard 4.
1) Hire 100 hackers
2) use their code to crack every bank and utility at once
3) kill the hackers.
4) profit!
Killing all his staff did leave him vulnerable to being tracked by Kevin Smith and taken down by a plucky former LAPD cop though.
Throw out a virtual net and pull 'em in. Maybe even pay out some money and recruit repeatedly. It might even attract the attention of the real 'gang'.
It does sound like a hollywood plot. You wouldn't want 100 people giving away the secrets, and it's not necessary when hackers use computers.
There's two sets of crooks involved here, one set are crooks trying to steal stuff, other set are crooks trying to get budget for security theatre. My guess is that this comes from the latter rather than the former.
Why use a hacker when you can use a banker?
What's wrong with insider attacks such as used by certain banks and financial institutions within the not-so-distant past? Best of all, when you use a banker, you get a tax-payer-funded bailout aka welfare, and you don't have to pay it back!
Most likely thing here is RSA is marketing their logon security tokens used by banks exactly to mitigate this sort of attack.
Duplicating a users compromised machine on a botmasters machine... why would you do that? You already control the end users machine! Why would you go to such an extent??
Also the 'VOIP' flood to stop the user contacting their bank? Rubbish. Hollywood plot stuff.
No it looks like PR timed to coincide with that European DDOS test to market RSA.
Comment removed based on user account deletion
Bullshit: if this were really happening, this guy would not be aware of it.
Also, the gang will only share executable files with their partners, and will not give up the Trojan's compilers, keeping the recruits dependent on the gang for updates
It's a trap! Who's that fucking stupid?
"You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
Why are they engaging in such theatrics? So far, most banks in the US don't even use two factor authentication (no, it's not a panacea, but it helps, in particular against man in the middle attacks).
I would get involved in this project solely so I could tell people I worked with RSA's F.A.R.T.
...I'd suggest this whole thing have been set up by the banks themselves as the first step in a larger plot. This is the first step (create an issue). The next step would be a large scale attack that will knock down the servers of the bank in which the key senators and representatives hold their assets (make the issue personal). Next, stage a series of arrests and claim the credit (present a solution). And finally, ask the government for additional protection measures for corporations, and other legislative means like on-demand personal data disclosure, ban on encrypted data transfers outside of banking systems, Internet 'kill-switch' and so on (profit).
But since I'm not a conspiracy theorist I'd say this is all just a scam. "Looking for bestest haxorz in teh wurld. Profit guaranteed, tools and training provided for a small entry fee" kind of thing. It's funny how RSA actually thinks this is some kind of "hack of the millennium" in making :)
Based on the title and summary one would think that RSA is looking to hire some whitehats to help.
This is not the case.
on the banking system with the Iranians being blamed for it...
Donald 'Duck' Dunn: We had a band powerful enough to turn goat piss into gasoline.
What's the acronym for "Fraud Action Research Team"?
“This Trojan is not well known. This is not SpyEye or Citadel; it’s not available for everyone to buy,” Ahuvia said. “Security vendors and antivirus signatures are less likely to catch it or be familiar with it. It will be tricky for vendors to detect and block it. This gang is keeping a tight hold on the compiler. By only giving up executable files, they can control how any antivirus signatures are in the wild and keep unique signatures to a minimum.” Again seems plausible. OK
Can you say "Live Free or Die"?