{"id":5523,"date":"2014-07-04T16:28:39","date_gmt":"2014-07-04T08:28:39","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=5523"},"modified":"2014-07-04T16:26:21","modified_gmt":"2014-07-04T08:26:21","slug":"cybercriminals-stole-half-a-million-in-just-one-week","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2014\/07\/04\/cybercriminals-stole-half-a-million-in-just-one-week\/","title":{"rendered":"Cybercriminals stole half a million Euros in just one week"},"content":{"rendered":"<p>The experts at Kaspersky Lab\u2019s Global Research and Analysis Team (GReAT) have discovered evidence of a targeted attack against the clients of a large European bank.<\/p>\n<p>According to the logs found in the server used by the attackers, apparently in the space of just one week cybercriminals stole more than half a million Euros from accounts in the bank.<\/p>\n<p>The first signs of this campaign were discovered on January 20 this year when Kaspersky Lab\u2019s experts detected a C&amp;C (Command and Control) server on the net.<\/p>\n<p>The server\u2019s control panel indicated evidence of a Trojan program used to steal money from clients\u2019 bank accounts.<\/p>\n<p>The experts also detected transaction logs on the server, containing information about which sums of money were taken from which accounts.<\/p>\n<p>All in all, more than 190 victims could be identified, most of them located in Italy and Turkey. The sums stolen from each bank account, according to the logs, ranged between 1,700 to 39,000 Euros (more than 2 million pesos).<\/p>\n<p>The campaign was at least one week old when the C&amp;C was discovered, having started no later than January 13, 2014.<\/p>\n<p>In that time, the cybercriminals successfully stole more than 500,000 Euros ( almost 30 million pesos). Two days after GReAT discovered the C&amp;C server, the criminals removed every shred of evidence that might be used to trace them.<\/p>\n<p>However, experts think this was probably linked to changes in the technical infrastructure used in the malicious campaign rather spelling the end of the Luuuk campaign.<\/p>\n<p>\u201cSoon after we detected this C&amp;C server, we contacted the bank\u2019s security service and the law enforcement agencies, and submitted all our evidence to them,\u201d said Vicente Diaz, Principal Security Researcher at Kaspersky Lab.<\/p>\n<p><strong>Malicious tools used<\/strong><\/p>\n<p>In the Luuuk case, experts have grounds to believe that important financial data was intercepted automatically and fraudulent transactions were carried out as soon as the victim logged onto their online bank accounts.<\/p>\n<p>\u201cOn the C&amp;C server we detected there was no information as to which specific malware program was used in this campaign. However, many existing Zeus variations (Citadel, SpyEye, IceIX, etc.) \u2013 have that necessary capability. We believe the malware used in this campaign could be a Zeus flavor using sophisticated web injects on the victims,\u201d Diaz added.<\/p>\n<p><strong>Money divestment schemes<\/strong><\/p>\n<p>The stolen money was passed on to the crooks\u2019 accounts in an interesting and unusual way.<\/p>\n<p>Kaspersky&#8217;s experts noticed a distinctive quirk in the organization of the so-called \u2018drops\u2019 (or money-mules), where participants in the scam receive some of the stolen money in specially created bank accounts and cash out via ATMs.<\/p>\n<p>There were evidences of several different \u2018drop\u2019 groups, each assigned with different sums of money. One group was responsible for transferring sums of 40-50,000 Euros (more than 2 million pesos), another with 15-20,000 (more than 1 million pesos) and the third with no more than 2,000 Euros (more than 100 thousand pesos).<\/p>\n<p>\u201cThese differences in the amount of money entrusted to different drops may be indicative of varying levels of trust for each \u2018drop\u2019 type. We know that members of these schemes often cheat their partners in crime and abscond with the money they were supposed to cash. The Luuuk\u2019s bosses may be trying to hedge against these losses by setting up different groups with different levels of trust: the more money a \u2018drop\u2019 is asked to handle, the more he is trusted,\u201d Diaz explained.<\/p>\n<p>The C&amp;C server related to The Luuuk was shut down shortly after the investigation started.<\/p>\n<p>However, the complexity level of the MITB operation suggests that the attackers will continue to look for new victims of this campaign.<\/p>\n<p>Kaspersky Lab\u2019s experts are engaged in an on-going investigation in The Luuuk\u2019s activities.<\/p>\n<p><strong>Kaspersky Fraud Prevention vs. the Luuuk<\/strong><\/p>\n<p>The evidence uncovered by Kaspersky Lab\u2019s experts indicates that the campaign was most probably organized by professional criminals.<\/p>\n<p>However, the malicious tools they used to steal money can be countered effectively by security technologies. For instance, Kaspersky Lab has developed Kaspersky Fraud Prevention \u2013 a multi-tier platform to help financial organizations protect their clients from online financial fraud.<\/p>\n<p>The platform includes components that safeguard client devices from many types of attacks, including Man-in-the-Browser attacks, as well as tools that can help companies detect and block fraudulent transactions.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The experts at Kaspersky Lab\u2019s Global Research and Analysis Team (GReAT) have discovered evidence of a targeted attack against the clients of a large European bank. According to the logs found in the server used by the attackers, apparently in the space of just one week cybercriminals stole more than half a million Euros from [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":5522,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[495],"class_list":["post-5523","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-cybersecurity-and-cybercrime"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/5523","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=5523"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/5523\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/5522"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=5523"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=5523"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=5523"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}