RSA Catches Financial Phishing Kit

Published: Jan 10, 2007
Updated: Feb 2, 2021
3 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

RSA, The Security Division of EMC, announced Jan. 10 that it has identified a new phishing kit that was being sold and used online by hackers to target users personal information in real time.

The phishing kit, known as a Universal Man-in-the-Middle Phishing Kit, is meant to help online hackers create attacks involving financial organizations by enabling the hacker to create a fake URL through a user-friendly online interface. The fraudulent URL communicates with the legitimate Web site of the targeted organization in real time.

The target receives a standard phishing e-mail, and if the target clicks on the link, he or she is sent to the fake URL. The target thinks that he or she is working with content from the legitimate Web site, but in fact, the fake URL allows hackers to access the targets personal information, RSA said.

/zimages/5/28571.gifPhishers are increasingly targeting financial institutions.Click hereto read more.

“As institutions put additional online security measures in place, inevitably the fraudsters are looking at new ways of duping innocent victims and stealing their information and assets,” Marc Gaffan, director of marketing for Consumer Solutions at RSA Security, based in Bedford, Mass., told eWEEK.

The new phishing kit was uncovered by RSAs AFCC (Anti-Fraud Command Center), a 24/7 team of 40 trained fraud analysts that work to mitigate online fraud.

The AFCC handled the kit by using an extensive monitoring and detection network, a broad blocking network and its site-shutdown capabilities.

“Using various technologies and procedures, the AFCC detects phishing attacks, analyzes them and works to shut them down on behalf of our FraudAction customers,” Gaffan said.

/zimages/5/28571.gifFor advice on how to secure your network and applications, as well as the latest security news, visit Ziff Davis InternetsSecurity IT Hub.

RSA analysts said the phishing kit has two main benefits for hackers. One, the hacker does not have to purchase or prepare a custom phishing kit for the organization being targeted, and two, the attack can intercept any type of credentials that are sent in to the site after the user has logged into his or her account.

Advertisement

“While these types of attacks are still considered next-generation, we expect them to become more widespread over the course of the next 12-18 months,” Gaffan said.

However, Gaffan said the AFCC will continue to shut down these kinds of attacks.

“The analysts at the AFCC work around the clock on behalf of the banks, so the banks can outsource the headache of detecting, shutting down and dealing with attacks in general,” Gaffan said. “The AFCC has vast experience in the industry and deep expertise in online fraud and banks can benefit from that and enjoy the economies of scale.”

The AFCC service varies in price depending on the type of service a bank selects as well as the size of the bank.

Check out eWEEK.coms Security Center for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at Ryan Naraines eWEEK Security Watch blog.

Patrick Hoffman

Patrick Hoffman

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。