Reuters

Write Comment     |     E-Mail To a Friend     |     Facebook     |     Twitter     |     Print


SAN FRANCISCO: Two of the most pervasive and dangerous types of software for stealing money from bank accounts have been improved and can now transfer money out automatically, without a hacker’s supervision, researchers said.
 
The latest variants of the widespread SpyEye and Zeus programmes have already stolen as much as 13,000 euros ($16,487) at a time from a single account and are in the early stages of deployment, according to investigators at Trend Micro, a Japan-based security company that has many banks as customers.
 
Trend Micro Vice President Tom Kellerman told Reuters that his company’s researchers had seen the new attacks on a dozen financial institutions in Germany, the United Kingdom and Italy. That is troubling because European banks generally have greater technology defenses than those in the United States, and Kellerman said it is "inevitable" that the variants will cross the Atlantic.
 
The new code has the potential to dramatically escalate the amount being stolen from accounts and a years-old arms race between the banks and criminal groups that are often based in Eastern Europe.
 
"This has tremendous implications," especially as Americans move toward banking by phone, said Kellerman. "This attack toolkit ushers in a new era of bank heists."
 
Like other security companies, Trend Micro profits by selling software and services to institutions and consumers worried about online spying and account takeovers.
 
Though written and controlled by different groups, SpyEye and Zeus share the ability to be installed on computers that visit malicious websites or legitimate pages that have been compromised by hackers. Both programs are sold in the burgeoning underground hacking economy, where they can be customized or improved with additional modules like those just discovered.
 
The programs already have used a technique called "web injection" to generate new entry fields when victims log on to any number of banks or other sensitive websites. Instead of seeing a bank ask for an account number and password, for example, a victimized user sees requests for both of those and an ATM card number. Everything typed in then gets whisked off to the hacker, who later signs in and transfers money to an accomplice’s account.
 
Those transfers can be time-consuming, and the hacker has to think about how much can be sent out at once without drawing attention. Multiple, smaller transfers are preferable but take more time.
 
For the past year or more, some variants have also captured one-time passwords sent from the banks by text messages to client cell phones as an added security measure. But in those cases, a hacker had to be online within 30 or 60 seconds in order to use the one-time password.
 
The new software allows the criminal to siphon money out while he sleeps. It could significantly increase the number of hacked accounts and the speed with which they are drained.
 
Brett Stone-Gross, a senior security researcher with Dell unit Dell SecureWorks, said thieves "will be able to extract more money" with automation.
 
But he also said the landscape might not be transformed by the development, because the main limiting factor for crime groups is the number of accomplices, known as money mules, that they can hire to accept transfers from victim accounts. Automation will not lessen the need for mules, Stone-Gross said.
 
Based in Eastern Europe
 Trend Micro spoke online with sellers of the automated transfer modules who were based in Russia, Ukraine and Romania, where arrests and prosecutions are rare. Kellerman said the new software costs between $300 and $4,000 on top of the basic thieving tools, with customized jobs costing still more.
 
So far, the company has seen it run only on top of Microsoft’s Windows operating system, which is by far the most common for personal computers.
 
Banks generally make individuals whole for such losses if they are detected quickly. But recent versions of SpyEye and Zeus can present fake account balances to individual bank customers, so they might not realize their savings are being drained until too late.
 
Kellerman recommended that banks move more toward "out-of-band" authentication, such as direct phone calls to confirm online transfers.
 
In the United States, financial regulators last June also called for such checks and urged banks to explore newer technologies to combat internet fraudsters.

Write your Comments on this Article
Your Name
Native Place / Place of Residence
Your E-mail
Your Comment   You have characters left.
Security Validation
Enter the characters in the image above
    
Disclaimer: Please write your correct name and email address. Kindly do not post any personal, abusive, defamatory, infringing, obscene, indecent, discriminatory or unlawful or similar comments. Kemmannu.com will not be responsible for any defamatory message posted under this article.
Please note that under 66A of the IT Act, sending offensive or menacing messages through electronic communication service and sending false messages to cheat, mislead or deceive people or to cause annoyance to them is punishable. It is obligatory on kemmannu.com to provide the IP address and other details of senders of such comments, to the authority concerned upon request. Hence, sending offensive comments using kemmannu.com will be purely at your own risk, and in no way will Kemmannu.com be held responsible.
Similarly, Kemmannu.com reserves the right to edit / block / delete the messages without notice any content received from readers.




Symphony98 Releases Soul-Stirring Rendition of Len
View More

Rozaricho Gaanch April, 2024 - Ester issueRozaricho Gaanch April, 2024 - Ester issue
Final Journey Of Theresa D’Souza (79 years) | LIVE From Kemmannu | Udupi |Final Journey Of Theresa D’Souza (79 years) | LIVE From Kemmannu | Udupi |
Invest Smart and Earn Big!

Creating a World of Peaceful Stay!

For the Future Perfect Life that you Deserve! Contact : Rohan Corporation, Mangalore.Invest Smart and Earn Big! <P>Creating a World of Peaceful Stay! <P>For the Future Perfect Life that you Deserve! Contact : Rohan Corporation, Mangalore.


Final Journey Of Joe Victor Lewis (46 years) | LIVE From Kemmannu | Organ Donor | Udupi |Final Journey Of Joe Victor Lewis (46 years) | LIVE From Kemmannu | Organ Donor | Udupi |
Milagres Cathedral, Kallianpur, Udupi - Parish Bulletin - Feb 2024 IssueMilagres Cathedral, Kallianpur, Udupi - Parish Bulletin - Feb 2024 Issue
Easter Vigil 2024 | Holy Saturday | St. Theresa’s Church, Kemmannu, Udupi | LIVEEaster Vigil 2024 | Holy Saturday | St. Theresa’s Church, Kemmannu, Udupi | LIVE
Way Of Cross on Good Friday 2024 | Live From | St. Theresa’s Church, Kemmannu, Udupi | LIVEWay Of Cross on Good Friday 2024 | Live From | St. Theresa’s Church, Kemmannu, Udupi | LIVE
Good Friday 2024 | St. Theresa’s Church, Kemmannu | LIVE | UdupiWay Of Cross on Good Friday 2024 | Live From | St. Theresa’s Church, Kemmannu, Udupi | LIVE
2 BHK Flat for sale on the 6th floor of Eden Heritage, Santhekatte, Kallianpur, Udupi2 BHK Flat for sale on the 6th floor of Eden Heritage,  Santhekatte, Kallianpur, Udupi.
Maundy Thursday 2024 | LIVE From St. Theresa’s Church, Kemmannu | Udupi |Maundy Thursday 2024 | LIVE From St. Theresa’s Church, Kemmannu | Udupi |
Kemmennu for sale 1 BHK 628 sqft, Air Conditioned flatKemmennu for sale 1 BHK 628 sqft, Air Conditioned  flat
Symphony98 Releases Soul-Stirring Rendition of Lenten Hymn "Khursa Thain"Symphony98 Releases Soul-Stirring Rendition of Lenten Hymn
Palm Sunday 2024 at St. Theresa’s Church, Kemmannu | LIVEPalm Sunday 2024 at St. Theresa’s Church, Kemmannu | LIVE
Final Journey of Patrick Oliveira (83 years) || LIVE From KemmannuFinal Journey of Patrick Oliveira (83 years) || LIVE From Kemmannu
Carmel School Science Exhibition Day || Kmmannu ChannelCarmel School Science Exhibition Day || Kmmannu Channel
Final Journey of Prakash Crasta | LIVE From Kemmannu || Kemmannu ChannelFinal Journey of Prakash Crasta | LIVE From Kemmannu || Kemmannu Channel
ಪ್ರಗತಿ ಮಹಿಳಾ ಮಹಾ ಸಂಘ | ಸ್ತ್ರೀಯಾಂಚ್ಯಾ ದಿಸಾಚೊ ಸಂಭ್ರಮ್ 2024 || ಸಾಸ್ತಾನ್ ಘಟಕ್ಪ್ರಗತಿ ಮಹಿಳಾ ಮಹಾ ಸಂಘ | ಸ್ತ್ರೀಯಾಂಚ್ಯಾ ದಿಸಾಚೊ ಸಂಭ್ರಮ್ 2024 || ಸಾಸ್ತಾನ್ ಘಟಕ್
Valentine’s Day Special❤️||Multi-lingual Covers || Symphony98 From KemmannuValentine’s Day Special❤️||Multi-lingual Covers || Symphony98 From Kemmannu
Rozaricho Gaanch December 2023 issue, Mount Rosary Church Santhekatte Kallianpur, UdupiRozaricho Gaanch December 2023 issue, Mount Rosary Church Santhekatte Kallianpur, Udupi
An Ernest Appeal From Milagres Cathedral, Kallianpur, Diocese of UdupiAn Ernest Appeal From Milagres Cathedral, Kallianpur, Diocese of Udupi
Diocese of Udupi - Uzvd Decennial Special IssueDiocese of Udupi - Uzvd Decennial Special Issue
Final Journey Of Canute Pinto (52 years) | LIVE From Mount Rosary Church | Kallianpura | UdupiFinal Journey Of Canute Pinto (52 years) | LIVE From Mount Rosary Church | Kallianpura | Udupi
Earth Angels Anniversary | Comedy Show 2024 | Live From St. Theresa’s Church | Kemmannu | UdupiEarth Angels Anniversary | Comedy Show 2024 | Live From St. Theresa’s Church | Kemmannu | Udupi
Confraternity Sunday | St. Theresa’s Church, KemmannuConfraternity Sunday | St. Theresa’s Church, Kemmannu
Kemmannu Cricket Match 2024 | LIVE from KemmannuKemmannu Cricket Match 2024 | LIVE from Kemmannu
Naturya - Taste of Namma Udupi - Order NOWNaturya - Taste of Namma Udupi - Order NOW
New Management takes over Bannur Mutton, Santhekatte, Kallianpur. Visit us and feel the difference.New Management takes over Bannur Mutton, Santhekatte, Kallianpur. Visit us and feel the difference.
Focus Studio, Near Hotel Kidiyoor, UdupiFocus Studio, Near Hotel Kidiyoor, Udupi