Showing posts with label banking. Show all posts
Showing posts with label banking. Show all posts

Sunday, December 15, 2019

Trend Micro warns of Trickbot’s updated password-grabbing module targeting more apps, services

Researchers from Trend Micro’s Security Intelligence have reported on a sudden increase of Trickbot’s activities in Japan, and Trend Micro researchers have found updates to the password-grabbing (pwgrab) module and possible changes to the Emotet variant that drops Trickbot.

Trickbot has been one of the most active banking trojans in 2019. The malware is constantly being improved with new and updated modules, and the threat actors behind it are still churning out new ones. Previous Trickbot reports involved behavior that compromises services and platforms to collect credentials from browser, Outlook, WinSCP, and FileZilla. 


Trend Micro’s latest report of changes to its pwgrab module found additional credential-stealing capabilities for remote access applications such as remote desktop protocol (RDP), virtual network computing (VNC), and PuTTY platforms. 

The most recent iterations (detected by Trend Micro as TrojanSpy.Win32.TRICKBOT.TIGOCER) targeted a slew of credentials from TeamViewer, OpenSSH, OpenVPN, Git, KeePass Password Manager, SSH private key files, SSL certificate files, and Bitcoin wallet files.

Due to its modular nature, Trickbot can and will surely morph into something more in order to add to its features, and cybercriminals will surely look into other possible iterations to make a profit. 


To address this challenge, enterprises can look into sourcing third-party security services offering managed detection and response (MDR), such as Trend Micro Managed XDR, which offers a wide scope of visibility and expert security analytics by integrating detection and response functions across networks, endpoints, emails, servers, and cloud workloads. Organizations will have access to the whole knowledge base of Trend Micro, including prior analysis of other Trickbot variants and other similarly sophisticated threats.

Moreover, enterprises can benefit from security technology that employs a multilayered approach to mitigate the risks brought by threats like Trickbot. 

Trend Micro XGen security provides a cross-generational blend of threat defense techniques to protect systems from all types of threats, including banking trojans, ransomware, and cryptocurrency-mining malware. It features high-fidelity machine learning on gateways and endpoints, and protects physical, virtual, and cloud workloads. 


With capabilities like web/URL filtering, behavioral analysis, and custom sandboxing, XGen security protects against today’s threats with various capabilities: bypassing traditional controls; exploiting known, unknown, or undisclosed vulnerabilities; or stealing or encrypting personally identifiable data. Smart, optimized, and connected, XGen security powers Trend Micro’s suite of security solutions.

Friday, December 13, 2019

Kaspersky reports that malware variety grew by 13.7 percent this year, driven by surge in web skimmers

The number of unique malicious objects detected by Kaspersky’s web antivirus solution rose by 13.7 percent this year, compared to last year, reaching 24,610,126. The growth was mainly influenced by a 187 percent rise in web skimmer files. 

Other threats, such as backdoors and banking Trojans detected in-lab, also grew, while the presence of miners dropped by more than half. These trends demonstrated a shift in the type of threats used by attackers on the web, who search for more effective ways to target users, according to the new Kaspersky Security Bulletin: Statistics of the Year report.


In 2018, unique malicious objects (including scripts, exploits and executable files) detected by Kaspersky’s web antivirus solution totaled 21,643,946, rising to 24,610,126 this year. The growth reflects an increase in the number and variety of HTML pages and scripts with hidden data loading – usually used by unscrupulous advertisers. Yet, most notably, the growth was also partially caused by online skimmers, sometimes referred to as sniffers, where scripts are embedded by attackers in online stores and used to steal users’ credit card data from websites.

The growth of online skimmers’ unique files (scripts and HTML) detected by Kaspersky web antivirus equaled 187 percent, reaching 510,000. At the same time, the number of threats detected by web antivirus has risen five-fold (by 523 percent), totaling 2,660,000 in 2019. 

Web skimmers also entered the top 20 malicious objects detected online, taking 10th place in the overall ranking. The share of new backdoors and banking Trojan files, among all types of threats detected in-lab, also grew by 134 percent and 61 percent to reach 7,644,402 and 739,551 respectively.

Nevertheless, the number of unique malicious URLs detected by Kaspersky web antivirus fell by half (50.5 percent) in comparison to 2018, from 554,159,621 to 273,782,113. This shift was largely caused by significant decrease of hidden web miners, even though several detections related to them (including Trojan.Script.Miner.gen, Trojan.BAT.Miner.gen, Trojan.JS.Miner.m), can still be seen in the top 20 web malware threats.


The presence of programs that secretly generate cryptocurrency on users’ computers (called ‘local’ miners) has also been steadily declining over the year. The number of users’ computers affected by attempts to install miners dropped by 59 percent, from 5,638,828 to 2,259,038.

Eighty-five percent of web threats were detected as malicious URL. This detection name is used to identify links from Kaspersky’s black list. It includes links to web pages containing redirects to exploits, sites with exploits and other malicious programs, botnet command and control centers, extortion websites, and others.

“The volume of online attacks has been growing for years, but in 2019 we saw a clear shift from certain types of attacks that are becoming ineffective, to the ones focused on gaining clear profit from users,” said Vyacheslav Zakorzhevsky, head of anti-malware research at Kaspersky. “This is partly due to users becoming more aware of the threats and how to avoid them, and organizations steadily becoming more responsible. A good example is miners, which have lost their popularity due to lower profitability and cryptocurrencies’ fight against covert mining. This year we also witnessed growth in zero-day exploits, showing products remain vulnerable and are used by attackers for sophisticated attacks, and this trend is likely to continue in the future.”

Monday, December 9, 2019

FBI frames charges against two Russians engaged in cybercrime scheme that infected computers in a malware conspiracy

The U.S. Department of Justice has joined with the U.S. Department of State and the United Kingdom’s National Crime Agency in charging two Russian nationals with a vast and long-running cybercrime spree that stole from thousands of individuals and organizations in the United States and abroad. 

Along with several co-conspirators, Maksim V. Yakubets and Igor Turashev are charged with an effort that infected tens of thousands of computers with a malicious code called Bugat. Once installed, the computer code, also known as Dridex or Cridex, allowed the criminals to steal banking credentials and funnel money directly out of victims’ accounts. 


Turashev and Yakubets were both indicted in the Western District of Pennsylvania on conspiracy to commit fraud, wire fraud, and bank fraud, among other charges. Yakubets was also tied to charges of conspiracy to commit bank fraud issued in the District of Nebraska after investigators were able to connect him to the indicted moniker “aqua” from that case, which involved another malware variant known as Zeus.

The long-running scheme involved a number of different code variants, and later version also installed ransomware on victim computers. The criminals then demanded payment in cryptocurrency for returning vital data or restoring access to critical systems. 

Assisted in some cases by money mules who funneled the stolen funds through U.S. bank accounts before shipping the money overseas, the group stole or extorted tens of millions of dollars from victims. Among those affected was a Pennsylvania school district that saw $999,000 wired out of its accounts and an oil company that lost more than $2 million.

The FBI, in partnership with the State Department’s Transnational Organized Crime Rewards Program, also announced a reward of up to $5 million for information leading to the arrest of Yakubets, who is alleged to be the leader of the scheme. The reward is the largest ever offered for a cyber criminal.

“The actions highlighted today, which represent a continuing trend of cyber-criminal activity emanating from Russian actors, were particularly damaging as they targeted U.S. entities across all sectors and walks of life,” said FBI Deputy Director David Bowdich. “The FBI, with the assistance of private industry and our international and U.S. government partners, is sending a strong message that we will work together to investigate and hold all criminals accountable.”


According to the charges, the co-conspirators distributed the malware through email phishing campaigns. In the early years, these messages were sent in massive, widespread campaigns. More recent attacks have been more strategic—specifically targeting businesses and organizations that have valuable computer systems and access to significant financial resources.

Victims were tricked into opening a document or clicking on a graphic or link that appeared to be from a legitimate source. The link or attachment downloaded the malicious code onto the user’s machine, where it could also spread to any networked computers.

According to FBI Supervisory Special Agent Steven Lampo, this campaign deployed a stealth type of malware designed to avoid detection by antivirus software. “The full program does too much and is too big to avoid detection,” Lampo said. The smaller piece of code, however, can inject itself into the running processes of the machine—beginning a process that allows the full suite of malware to load onto the machine or network. The malware’s creators were constantly creating new variants of the code to avoid antivirus tools.

“Although their realm is a digital one, this is one of the world’s largest organized crime groups,” said FBI Supervisory Special Agent Adam Lawson of the Major Cyber Crimes Unit. “They are personally getting rich, and new organizations and individuals are being victimized every day.”

Turashev and Yakubets were both indicted in the Western District of Pennsylvania on conspiracy to commit fraud, wire fraud, and bank fraud, among other charges. Yakubets was also tied to charges of conspiracy to commit bank fraud issued in the District of Nebraska after investigators were able to connect him to the indicted moniker “aqua” from that case, which involved another malware variant known as Zeus.

Thursday, December 5, 2019

Visure Solutions releases easy-to-use web interface for Requirements Management ALM offering

Visure Solutions Inc., a requirements Application Lifecycle Management (ALM) company, has launched Visure Web Reviewer 5.0, an intuitive and easy-to-use web interface. Allowing users to review and approve requirements, test and design specifications through an easy-to-use, the web interface reduces the challenges many teams face in the entire product-to-market process. 

The web-based version will allow any type of stakeholder (technical and non-technical users) of RM – including, but not limited to marketing teams, management teams, customers and suppliers – to navigate the sometimes complex ALM process. 


 As companies become increasingly aware of the importance of managing risk and improving their development process, Requirements Management (RM) will play a more crucial role in coordinating with different stakeholders and customer needs.

However, many of today's RM tools pose technical challenges for several of those stakeholders, creating bottlenecks and frustration in the product development lifecycle. 


Visure Reviewer web-based interface will also help increase efficiency and optimize processes while speeding the product development process by saving time, strengthening alignment, and ensuring quality and compliance.

"Visure Reviewer's web release is simpler and easier to use and will basically bridge the gap between technical and non-technical teams that have been isolated in the past," said Dr. Moustapha Tadlaoui, Visure's CEO. "This new version will enable better communication between teams and help them collaborate in a much tighter way, which will improve productivity, address the causes for project delays and failures and contribute to project success, and help them deliver a better-quality product." 


"Requirements management is an intensive undertaking. We designed the platform to make it easier to track, test, analyze, visualize, and communicate to all stakeholders," said Visure CTO Fernando Valera. "Visure's new Reviewer web-based tool empowers cross-functional collaboration and alignment between business, compliance, and technology stakeholders throughout the product development lifecycle."

The platform – which comes on the heels of the launch of Visure's comprehensive ALM platform – is expected to open new vertical markets for the company, including banking, administration and insurance.


"Requirements management tools are becoming more approachable and better integrated with daily development activities, empowering organizations to succeed with agility at scale across many industries," Tadlaoui said. "By expanding to other vertical and geographical markets, Visure plans to help our growing customer base achieve compliance and improve their lifecycle processes."

Thursday, November 7, 2019

IBM releases financial services- ready public cloud platform to meet specific compliance and security requirements

IBM announced this week that it has designed a financial services-ready public cloud. IBM will welcome financial services institutions, and their suppliers, to join the financial services-ready public cloud. 

The financial services-ready public cloud is expected to run on IBM's public cloud, which uses Red Hat OpenShift as its primary Kubernetes environment to manage containerized software across the enterprise, and includes more than 190 API driven, cloud native PaaS services to create new and enhanced cloud-native apps. 


The project draws upon technology and financial services industry experience earned through IBM's relationships with 47 of the Fortune 50 companies and the 10 largest financial institutions globally.  Additionally, to help promote a regulatory compliant environment, IBM and Bank of America are working with Promontory, an IBM business unit and provider of financial services regulatory compliance consulting. 

Bank of America will be a committed collaborator to use the platform built on IBM's public cloud. The Bank will host key applications and workloads to support the requirements and privacy and safety expectations of its 66 million banking customers. 

The financial services-ready public cloud has been designed to help address the requirements of financial services institutions for regulatory compliance, security and resiliency. This will help financial institutions transact with technology vendors who have met the platform's requirements. 


It is the only industry-specific public cloud platform that can provide preventative and compensatory controls for financial services regulatory workloads, multi-architecture support and proactive and automated security, leveraging the industry's highest levels of encryption certification.

To help develop the control requirements for the platform, IBM has collaborated intensively with Bank of America. The financial services-ready public cloud can potentially enable Independent Software Vendors (ISVs) and Software-as-a-Service (SaaS) providers – from the smallest FinTechs to more established vendors – to focus on their core offerings to financial institutions with the controls for the platform put in place.

"This is one of the most important collaborations in the financial services industry cloud space," said Cathy Bessant, chief operations and technology officer, Bank of America. "This industry-first platform will allow Bank of America to use the public cloud, putting data security, resiliency, privacy and customer information safety needs at the forefront of decision making. By setting a standard that addresses the concern of hosting highly-confidential information, we aim to drive the public cloud to a safety level that is unmatched."

The collaboration with IBM marks the next step in Bank of America's seven-year cloud journey and reflects the Bank's unwavering commitment to the security and privacy of banking customers while also creating an opportunity to address the unique regulatory and compliance requirements of the financial services industry.  


"The financial services-ready public cloud represents an ongoing focus from Bank of America, IBM and Promontory to help develop a technology ecosystem where regulations can be addressed," said Bridget van Kralingen, Senior Vice President, Global Industries, Clients, Platforms & Blockchain, IBM. "Together we plan to help our customer address their ongoing compliance requirements, coupled with highly scalable, standardized capabilities that will be built to help serve today's modern financial services industry." 

"We recognize that we must help create an environment where financial services institutions can address their regulatory requirements and expectations," said Gene Ludwig, Promontory Founder and CEO. "Bank of America, IBM and Promontory are uniquely suited to help give the industry and vendors confidence in the quality of this cloud platform." 

The financial services-ready public cloud will help give financial institutions an opportunity to more efficiently assess the security, resiliency and compliance of their technology vendors. Participating financial services software providers may benefit from the platform's security validation. Only ISV or SaaS providers that demonstrate they comply with the platform's policies will be eligible to deliver offerings through the platform.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...