Wanted: Hackers For Large-Scale Attacks On American Banks
Trailrunner7 writes "RSA's FraudAction research team has been monitoring underground chatter and has put together various clues to deduce that a cybercrime gang is actively recruiting up to 100 botmasters to participate in a complicated man-in-the-middle hijacking scam using a variant of the proprietary Gozi Trojan. This is the first time a private cybercrime organization has recruited outsiders to participate in a financially motivated attack, said Mor Ahuvia, cybercrime communications specialist for RSA FraudAction. The attackers are promising their recruits a cut of the profits, and are requiring an initial investment in hardware and training in how to deploy the Gozi Prinimalka Trojan, Ahuvia added. Also, the gang will only share executable files with their partners, and will not give up the Trojan's compilers, keeping the recruits dependent on the gang for updates."
The attackers are promising their recruits a cut of the profits, and are requiring an initial investment in hardware and training
as any confidence man could tell you, the best marks are those that think they are in on the scam...
Can I apply right now?
Why bother recruiting people if you can just hire bots, or herd your own? Why go for 100 small ones if just a few bigger ones will yield you the same number of victims?
These seem like either very inexperienced criminals, or indeed, as someone else suggested, scammers that want to rip off botnet herders, not banks. You don't involve people in your gang if you don't absolutely need them. You don't train them, unless you absolutely need them to know things. The less people know as little as possible, the smaller the chance you will get caught. Causing a racket by recruiting up to 100 herders does not fit that MO.
I was promised a flying car. Where is my flying car?
I'm trying to remember, who are the bad guys here, the law-breaking, savings-stealing douchebags, or the guys running the botnet?
They should be hacking banks using OPEN SOURCE SOFTWARE and tools. (Strokes beard thoughtfully.) The use of proprietary, closed-source tools takes away from the common, computer using felon the ability to maintain his own malicious code.
~ Richard Stallman
May God the merciful grant you peace. You will be surprised to hear from me. I am MRS. HELENA SHOSTAKOVICH, widow of the late DMITRI SHOSTAKOVICH of hacker fame. My dear husband past away two weeks ago, leaving behind 1,500,000 credit card numbers worth THREE HUNDRED MILLIONS US DOLLARS. As I am unable to realize this sum here in Russia, I have been authorized to advance into your bank account FIVE MILLION DOLLARS for assistance in retrieving this funds. The requirement from you, to show you are an honest man of principle and good faith, is an insignificant small purchase of hardware from the following list: ...
To avoid Putin's spies, I have retained agents in NIGERIA who will handle your transactions. Forward your credit card particulars to:
Mr. JOHN MBUTU
POST OFFICE WILL CALL
LAGOS, NIGERIA
#DeleteChrome
Comment removed based on user account deletion
Bullshit: if this were really happening, this guy would not be aware of it.