Tampilkan postingan dengan label Banking Malware. Tampilkan semua postingan


Spanish Police have arrested a gang of 11 cyber criminals as part of Operation Ransom who allegedly ran ransomware network to demand money from thousands of victims in 30 countries using malware known as Reveton.




It�s believed the cyber criminals have managed to invest tens of thousands of computers and make a profit of over 1 million EUR ($1.34 million) per year.


Eleven individuals have been arrested as part of Operation Ransom, one of them, a 27-year-old Russian national, being suspected of developing and distributing various versions of the malware. The Russian was arrested in the United Arab Emirates. He will be extradited to Spain in the upcoming period.

In addition to apprehending the mastermind of the operation, authorities have also dismantled the group�s largest financial cell, located in Costa del Sol, Spain. Six Russians, two Georgians and two Ukrainians have been arrested by Spanish police.

During the raids on six locations in the province of M�laga, investigators seized IT equipment, and credit cards that the crooks had used to cash out the money that their victims paid via MoneyPak, Ukash, and Paysafecard.

The financial cell was in charge of laundering the money they extorted from Internet users. Virtual coins, electronic payment gateways and even online gaming portals have been used by the crooks to launder the proceeds.

The suspects have also utilized hijacked credit cards to withdraw money from ATMs located in Spain.

Since May 2011, when the ransomware was first discovered, 1,200 cases have been reported in Spain alone. However, it�s worth noting that not all victims file complaints, so it�s likely that the number of affected users is much higher.
Description: Spanish Police arrested group behind Ransomware network
Rating: 4.5
Reviewer: Unknown
ItemReviewed: Spanish Police arrested group behind Ransomware network
The home Trojan-banker known as Shylock has updated with new functions. It is noticed that Shylock is now capable of spreading using the popular Voice over IP service and software application, Skype. This allows the malicious Trojan-banker to infect more hosts and continue to be a prevalent threat, according to CSIS Security Group.


Shylock is one of the most advanced Trojan-banker currently being used in attacks against home banking systems. The code is constantly being updated and new features are added regularly.

The Skype infection is based on a malicious plugin called msg.gsm and allows the malware to send messages and transfer files, clean messages and transfers from Skype history and even bypass the Skype warning for connecting to servers.

Besides from utilizing Skype it will also spread through local shares and removable drives. Basically, the C&C functions allow the attacker to:

- Execute files
- Get cookies
- Inject HTTP into a website
- Setup VNC
- Spread through removable drives
- Uninstall
- Update C&C server list
- Upload files

Currently, the Shylock detection ratio is zero, which shows its power with advance features. According to a map showing the distribution of Shylock infections that was published by CSIS, there's a high concentration of victims in the UK. However, there are also many Shylock-infected computers throughout mainland Europe and the US.
Description: Banking Malware Shylock spreads via Skype to target specific Countries
Rating: 4.5
Reviewer: Unknown
ItemReviewed: Banking Malware Shylock spreads via Skype to target specific Countries
Welcome to My Blog

Popular Post

Labels

Followers

- Copyright © 2013 shad0w-share | Designed by Johanes Djogan -