Infosec Europe 2008
Infosec Europe 2008
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Infosec: Rock Phish threat deepens

Hugely successful malware gets a new twist

Iain Thomson at Infosec Europe, vnunet.com 23 Apr 2008
ADVERTISEMENT

Security firm RSA has warned that the software kit behind half of the world's phishing attacks has been upgraded.

The Rock Phish software has been used in attacks on over 40 European and US financial institutions.

The tool has been very successful, using innovations including unique URL generation to defeat blacklists. But Rock Phish has not used malware as part of its attack until recently.

The fake phishing pages now include a Trojan dubbed Zeus, so that once a victim's financial data has been harvested the Trojan allows the computer to be controlled remotely.

"The victim is duped into visiting a phishing site," said Uriel Maimon from the RSA 24x7 Anti-Fraud Command Center.

"Whether or not the victim surrenders his/her credentials into the site is irrelevant, as many people click on phishing links but do not fill in meaningful information.

"However, with this new attack twist the victim will still be infected with a Trojan."

The group behind the Rock Phish attacks did not develop the Trojan themselves, but purchased it for the job in much the same way as a legal software developer.

Zeus is a very flexible and persistent Trojan which can be used to steal data, make the infected machine part of a botnet and even take regular screenshots of a user's activity.

"The Zeus Trojan has many startling capabilities," said Maimon. "As I look on this blissful union of fraud and crime technologies, I can only envy the criminals who can find such coupling."

The Rock Phish software has become something of a cause célèbre in the IT security industry since it surfaced.

The creators have been described as the Kaiser Söze of the online world, and no-one is sure whether the creator is a single person or a hacking group.

RSA is confident that it is a hacking group behind the code, and no-one disputes that the software has been astonishingly successful.

Hundreds of millions of pounds have been siphoned out of users' bank accounts over the past four years.

See also:

Infosec Europe 2008Lack of control and security fears outweigh benefits  23 Apr 2008
Infosec Europe 2008Security is now everyone's problem  23 Apr 2008
Infosec Europe 2008The latest news and views from Europe's number one information security event  01 May 2008

All Enterprise Security Technology
Tags: Infosec, Security

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Swindon, Wiltshire, United Kingdom | EDS
EDS are currently looking to recruit a Change, Risk and Issue Analyst to join our Project Management Defence team in Swindon, Wiltshire. Summary: The Regional Operations Cell Analyst will work as part of a small ... more >
Inverness, United Kingdom | NHS Scotland
CORPORATE SERVICES E-HEALTH DEPARTMENT  RAIGMORE HOSPITAL INVERNESS TECHNICAL DEVELOPMENT TEAM IT TECHNICAL SPECIALIST  £24,103 to £32,653 PA An exciting opportunity has arisen to join the technical development team within the eHealth Department. We are looking ... more >
Darmstadt, Germany | EUMETSAT
  UNIX Application Software Engineer - Darmstadt - £Competitive Formed in 1986 and comprising 21 European member states, EUMETSAT's role is to establish, operate and exploit European meteorological satellite systems. Data from these systems are essential for ... more >
London, United Kingdom | The Moving Picture Company
Web Developer - London   MPC's continued success is dependent on a continued investment in technology so that its clients continue to enjoy the highest possible quality of work and service. Key to MPC's offering is ... more >
More job opportunities