Information Security News mailing list archives

Bank man: System's down, let's have coffee. Oh SNAP, where's all the CASH?


From: InfoSec News <alerts () infosecnews org>
Date: Thu, 22 Aug 2013 05:53:24 +0000 (UTC)

http://www.theregister.co.uk/2013/08/21/cyberheist_ddos_smokescreen/

By John Leyden
The Register
21st August 2013

Cybercrooks are running distributed denial of service attacks as a smokescreen to distract bank security staff while they plunder online banking systems, according to a researcher.

Avivah Litan, vice president at Gartner Research, reports that cyber criminals looking to attack financial institutions are getting more ambitious by targeting the internal wire applications of entire banks, instead of individual accounts, and covering their tracks using simultaneous denial of service attacks against bank systems as a distraction.

Fraudulent money transfers have traditionally been pulled off by taking over a mark's bank account and moving money into accounts of “money mules”. The stolen cash is then passed around between mules until it ends up in the accounts of the cyber criminals. However, Litan says that the latest evolution of these attacks uses DDoSes as a cover for much more damaging attacks:

[...]

--
Find the best InfoSec talent without breaking your
recruiting budget! Post a Job, $99 for 31 days.
Hot InfoSec Jobs - http://www.hotinfosecjobs.com/

Current thread: