Showing posts with label Zeus. Show all posts
Showing posts with label Zeus. Show all posts

Monday, December 9, 2019

FBI frames charges against two Russians engaged in cybercrime scheme that infected computers in a malware conspiracy

The U.S. Department of Justice has joined with the U.S. Department of State and the United Kingdom’s National Crime Agency in charging two Russian nationals with a vast and long-running cybercrime spree that stole from thousands of individuals and organizations in the United States and abroad. 

Along with several co-conspirators, Maksim V. Yakubets and Igor Turashev are charged with an effort that infected tens of thousands of computers with a malicious code called Bugat. Once installed, the computer code, also known as Dridex or Cridex, allowed the criminals to steal banking credentials and funnel money directly out of victims’ accounts. 


Turashev and Yakubets were both indicted in the Western District of Pennsylvania on conspiracy to commit fraud, wire fraud, and bank fraud, among other charges. Yakubets was also tied to charges of conspiracy to commit bank fraud issued in the District of Nebraska after investigators were able to connect him to the indicted moniker “aqua” from that case, which involved another malware variant known as Zeus.

The long-running scheme involved a number of different code variants, and later version also installed ransomware on victim computers. The criminals then demanded payment in cryptocurrency for returning vital data or restoring access to critical systems. 

Assisted in some cases by money mules who funneled the stolen funds through U.S. bank accounts before shipping the money overseas, the group stole or extorted tens of millions of dollars from victims. Among those affected was a Pennsylvania school district that saw $999,000 wired out of its accounts and an oil company that lost more than $2 million.

The FBI, in partnership with the State Department’s Transnational Organized Crime Rewards Program, also announced a reward of up to $5 million for information leading to the arrest of Yakubets, who is alleged to be the leader of the scheme. The reward is the largest ever offered for a cyber criminal.

“The actions highlighted today, which represent a continuing trend of cyber-criminal activity emanating from Russian actors, were particularly damaging as they targeted U.S. entities across all sectors and walks of life,” said FBI Deputy Director David Bowdich. “The FBI, with the assistance of private industry and our international and U.S. government partners, is sending a strong message that we will work together to investigate and hold all criminals accountable.”


According to the charges, the co-conspirators distributed the malware through email phishing campaigns. In the early years, these messages were sent in massive, widespread campaigns. More recent attacks have been more strategic—specifically targeting businesses and organizations that have valuable computer systems and access to significant financial resources.

Victims were tricked into opening a document or clicking on a graphic or link that appeared to be from a legitimate source. The link or attachment downloaded the malicious code onto the user’s machine, where it could also spread to any networked computers.

According to FBI Supervisory Special Agent Steven Lampo, this campaign deployed a stealth type of malware designed to avoid detection by antivirus software. “The full program does too much and is too big to avoid detection,” Lampo said. The smaller piece of code, however, can inject itself into the running processes of the machine—beginning a process that allows the full suite of malware to load onto the machine or network. The malware’s creators were constantly creating new variants of the code to avoid antivirus tools.

“Although their realm is a digital one, this is one of the world’s largest organized crime groups,” said FBI Supervisory Special Agent Adam Lawson of the Major Cyber Crimes Unit. “They are personally getting rich, and new organizations and individuals are being victimized every day.”

Turashev and Yakubets were both indicted in the Western District of Pennsylvania on conspiracy to commit fraud, wire fraud, and bank fraud, among other charges. Yakubets was also tied to charges of conspiracy to commit bank fraud issued in the District of Nebraska after investigators were able to connect him to the indicted moniker “aqua” from that case, which involved another malware variant known as Zeus.

Tuesday, December 3, 2019

Kaspersky releases its financial threat predictions for 2020, as fintech, mobile banking and e-commerce are likely to intensify

According to Kaspersky experts, financially motivated cyberthreat actors may start to target investment apps, online financial data processing systems and upcoming cryptocurrencies in 2020. Additionally, experts predict they may offer paid access to banks’ infrastructures and develop new strains of mobile banking malware based on leaked source code.

Financial cyberthreats are considered to be some of the most dangerous, as their impact usually results in direct financial losses for victims. 2019 has seen some significant developments in the industry and also in how financial attackers operate. 


These events allowed Kaspersky researchers to suggest several important potential developments for the financial threat landscape for 2020. 

Fintech is under attack. Mobile investments apps have become more popular among users around the globe, and this trend won’t go unnoticed by cybercriminals in 2020. Not all of these apps utilize best security practices, like multi-factor authentication or protection of the app connection, which may give cybercriminals a potential way to target users of such applications

Kaspersky research and monitoring of underground forums suggests that the source code of some popular mobile banking Trojans was actually leaked into the public domain. Previous similar cases of malware source code leakage such as Zeus and SpyEye that resulted in an increased number of new variations of these Trojans. In 2020 this pattern may repeat.


In 2020, Kaspersky experts expect an increase in the activity of groups specialised in criminal-to-criminal sale of network access to banks in the African and Asian regions, as well as in Eastern Europe. Their prime targets are small banks as well as financial organizations recently bought by big players who are rebuilding their cybersecurity system in accordance with the standards of their parent companies. it is also expected that the same banks may become victims of targeted ransomware attacks, as banks are among those organizations that are more likely to pay a ransom than accept the loss of data.

Magecarting 3.0 features more cybercriminal groups will target online payment processing systems. Over the past couple of years, so-called JS-skimming (the method of stealing of payment card data from online stores) has gained immense popularity among attackers. 

Currently, Kaspersky researchers are aware of at least 10 different actors involved in these type of attacks and experts believe that their number will continue to grow during the next year. The most dangerous attacks will be on companies that provide services such as e-commerce as-a-service, which will lead to the compromise of thousands of companies.


“This year has been one of many important developments,” says Yuriy Namestnikov, a security researcher at Kaspersky. “Just as we predicted at the end of 2018, it has seen the emergence of new cybercriminal groups like CopyPaste, new geography of attacks by Silence group and cybercriminals shifting their focus to data that helps to bypass antifraud systems in their attacks. Behavioral and biometrics data is on sale on the underground market. Additionally, we expected JS-skimmer base attacks to increase and they did. With 2020 on the horizon, we recommend security teams in potentially affected areas of the finance industry to gear up for new challenges. There is nothing inevitable in potential upcoming threats, it is just important to be properly prepared for them.”

In addition to financial sector, Kaspersky researchers identified other industries that will face new security related challenges in the upcoming year, such as the healthcare industry is advised to focus on protecting medical records and connected medical devices, as they are becoming the target of threat actors. 

Corporate security teams should pay more attention to cloud infrastructure and also to addressing growing risks of insiders accessing their networks. There are groups of criminals specializing on recruiting insiders through various techniques, including blackmail. 

Telecommunications and other industries that vastly use cellular communications should be prepared to assess and address risks that will come with wider adoption of 5G, which is expected to start in 2020. 

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...