Online Bank-Theft Software Grows more Sophisticated

Jun 18, 2012 07:40 AM EDT

Share This Story

  • Print
  • Email

Two of the most pervasive and dangerous types of software for stealing money from bank accounts have been improved and can now transfer money out automatically, without a hacker's supervision, researchers said.

Follow us

The latest variants of the widespread SpyEye and Zeus programs have already stolen as much as 13,000 euros ($16,487) at a time from a single account and are in the early stages of deployment, according to investigators at Trend Micro Inc, a Japan-based security company that has many banks as customers.

Trend Micro Vice President Tom Kellerman told Reuters that his company's researchers had seen the new attacks on a dozen financial institutions in Germany, the United Kingdom and Italy. That is troubling because European banks generally have greater technology defenses than those in the United States, and Kellerman said it is "inevitable" that the variants will cross the Atlantic.

The new code has the potential to dramatically escalate the amount being stolen from accounts and a years-old arms race between the banks and criminal groups that are often based in Eastern Europe.

"This has tremendous implications," especially as Americans move toward banking by phone, said Kellerman. "This attack toolkit ushers in a new era of bank heists."

Like other security companies, Trend Micro profits by selling software and services to institutions and consumers worried about online spying and account takeovers.

Though written and controlled by different groups, SpyEye and Zeus share the ability to be installed on computers that visit malicious websites or legitimate pages that have been compromised by hackers. Both programs are sold in the burgeoning underground hacking economy, where they can be customized or improved with additional modules like those just discovered.

The programs already have used a technique called "web injection" to generate new entry fields when victims log on to any number of banks or other sensitive websites. Instead of seeing a bank ask for an account number and password, for example, a victimized user sees requests for both of those and an ATM card number. Everything typed in then gets whisked off to the hacker, who later signs in and transfers money to an accomplice's account.

Those transfers can be time-consuming, and the hacker has to think about how much can be sent out at once without drawing attention. Multiple, smaller transfers are preferable but take more time.

For the past year or more, some variants have also captured one-time passwords sent from the banks by text messages to client cell phones as an added security measure. But in those cases, a hacker had to be online within 30 or 60 seconds in order to use the one-time password.

The new software allows the criminal to siphon money out while he sleeps. It could significantly increase the number of hacked accounts and the speed with which they are drained.

Brett Stone-Gross, a senior security researcher with Dell Inc unit Dell SecureWorks, said thieves "will be able to extract more money" with automation.

But he also said the landscape might not be transformed by the development, because the main limiting factor for crime groups is the number of accomplices, known as money mules, that they can hire to accept transfers from victim accounts. Automation will not lessen the need for mules, Stone-Gross said.

BASED IN EASTERN EUROPE

Trend Micro spoke online with sellers of the automated transfer modules who were based in Russia, Ukraine and Romania, where arrests and prosecutions are rare. Kellerman said the new software costs between $300 and $4,000 on top of the basic thieving tools, with customized jobs costing still more.

So far, the company has seen it run only on top of Microsoft Corp's Windows operating system, which is by far the most common for personal computers.

Banks generally make individuals whole for such losses if they are detected quickly. But recent versions of SpyEye and Zeus can present fake account balances to individual bank customers, so they might not realize their savings are being drained until too late.

Kellerman recommended that banks move more toward "out-of-band" authentication, such as direct phone calls to confirm online transfers.

In the United States, financial regulators last June also called for such checks and urged banks to explore newer technologies to combat Internet fraudsters.

Get the Most Popular Mobile&Apps Stories in a Weekly Newsletter

Copyright 2013 Thomson Reuters. All rights reserved.

Join Our Conversation

Smartphones
Galaxy S4 Google EditionSamsung Galaxy S4 Google Edition: $649 Price Tag Explained
Nokia EOS Details Allegedly Leaked: Once Again Nokia Focuses On The Camera
Samsung Galaxy Note 3 May Sport Same Familiar Plastic Design, Not Metal
Intellicam App Brings First Hands-Free Camera Feature To Windows Phone 8
Tablet / Laptop / PC
Nexus 7Nexus 7 Refresh Teased In Google+ Hangouts Video, Sports Glowing Notification Light
AMD Unleashes Radeon 8900M Mobile GPU: Get It In MSI GX70 Gaming Laptop
Dell XPS 10 Drops Price To $300, Marking A New Low For Windows RT
HP Slatebook x2 Convertible Laptop Rocks Nvidia Tegra 4, Android 4.2 Jelly Bean
Gadgets
Google GlassGoogle Glass Raises Lawmakers' Concerns: Congress Demands Answers About Privacy
Seven New Apps Coming To Google Glass: Facebook, Twitter, And Evernote Included
Android 4.2.2 Jelly Bean, Chrome Update For Google TV: End Of Flash?
AMD Unleashes Radeon 8900M Mobile GPU: Get It In MSI GX70 Gaming Laptop
OS / Software
Samsung Galaxy S4 Gets TCO CertificationSamsung Galaxy S4 Gets TCO Certification
Android 4.3 Jelly Bean Coming On June 10: Absent From Google I/O 2013 Intentionally
Android 4.2.2 Jelly Bean, Chrome Update For Google TV: End Of Flash?
Google Wallet Update: Send Money To Friends With Gmail, Make One-Click Purchases On The Go
Internet / Social Media
The Yahoo logYahoo Is Eyeing Tumblr
Google I/O 2013: Chrome Web Browser Now Has 750 Million Active Users
Google I/O 2013: Google Maps Gets New UI And Google+ Hangouts Shows Massive Improvements
Gtalk Chat Integration Coming To Outlook.com
What's App
Intellicam Windows Phone 8Intellicam App Brings First Hands-Free Camera Feature To Windows Phone 8
Seven New Apps Coming To Google Glass: Facebook, Twitter, And Evernote Included
Itsdagram Available Now For Windows Phone: Best Instagram Client Around
Google I/O 2013: Chrome Web Browser Now Has 750 Million Active Users

DON'T MISS

Galaxy S4 White Frost
Verizon Samsung Galaxy S4 To Come On May 23
According to an update on Verizon's news page, the Galaxy S4 will now be available in Verizon
Galaxy S4 Google Edition
Samsung Galaxy S4 Google Edition Launched: Rumors Say It's Nexus 5
The new edition of the Galaxy S4 is being seen as an alternative to the Nexus smartphones as the
RIM BlackBerry 10
BlackBerry Live: 120,000 Apps in BlackBerry World, Gaining on Windows Phone
The numbers are in, and it appears BlackBerry World might walk over Windows Phone sooner or later.
Windows Blue
Windows 'Blue' Will Come As Free Update For Windows 8, Windows RT Users
Despite previous rumors, Windows 8.1 dubbed Windows 'Blue' will be available as a free update to
LG Google TV
Android 4.2.2 Jelly Bean, Chrome Update For Google TV: End Of Flash?
The Google TV has now be 'refactored' so the OEMs of the device can update their settop boxes to
Samsung Galaxy S4 'Blue Arctic'
Samsung Galaxy S4 Blue Arctic Gets Official On Docomo Network
Samsung Galaxy S4 Blue Arctic is real but it is not yet clear whether the handset is exclusively

Galaxy S4 White Frost
Samsung To Look Into 16GB Galaxy S4 Storage Woes, 'Software Optimization' Might Free More Space
Samsung has finally responded to storage woes concerning the 16GB Samsung Galaxy S4 and said it may
Samsung Galaxy S4 Mini 'Leaked' Image
Samsung Galaxy S4 Mini Spotted In Leaked Images Once Again
In the latest series of leaked pictures, the Galaxy S4 mini is shown from every possible angle and
Google Maps
Google I/O 2013: Google Maps Gets New UI And Google+ Hangouts Shows Massive Improvements
Fans of Google products will love the new look of Google Maps and Google+ Hangouts.
MSI GX70
AMD Unleashes Radeon 8900M Mobile GPU: Get It In MSI GX70 Gaming Laptop
Do you enjoy gaming on a laptop? The AMD Radeon 8900M might excite you along with the MSI GX70.
Copyright © 2013 Mobile & Apps All rights reserved. mobilenapps
Real Time Analytics