Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity

    Phishers Zero in on E-Banking

    Written by

    Paul F. Roberts
    Published October 10, 2005
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Scam artists who target online banking customers are adapting their techniques to try to defeat a range of sophisticated new security features designed to thwart phishing attacks, according to experts.

      In recent months, companies that monitor phishing attacks have noticed an increase in malicious programs that record computer screen activity. The rise in so-called screen scraping may be an attempt to counter new electronic banking programs that use a combination of mouse clicks and keyed entries to give customers access to their online accounts.

      While screen-scraping attacks are rare, experts agree that they are becoming more common and are even becoming a standard feature in malicious programs that can be custom-ordered online.

      /zimages/1/28571.gifSecurity Editor Larry Seltzer thinks IE 7 and its widespread use will make a real dent in phishing. Click here to read more.

      Websense Inc., a Web security software company, has seen an increase in screen-scraping programs in the last six months, especially in Brazil and other South American countries, said Dan Hubbard, senior director of security and technology research at Websense, in San Diego.

      /zimages/1/28571.gifIs Internet banking safer than you think? Click here to read more.

      The Trojan horse programs wait until the user of an infected machine visits an online banking site and then capture mouse interactions with the site, allowing the criminals controlling the Trojan to spy on interactions with on-screen keyboards that are designed to foil keylogging software.

      The new attacks come as more banks are deploying technology that combines mouse clicks with keyed information such as user names and passwords.

      Bank of America Corp. is deploying a program called SiteKey that uses technology from Passmark Security Inc. that requires customers to click on a preselected image in addition to entering their user name and password to log on to an account, said Betty Riess, a Bank of America spokesperson in San Francisco.

      Even if phishers could capture the users unique image, the Passmark service tracks what computer a banking customer is accessing the account from and uses challenge-response questions to weed out fraudsters.

      Malicious programs such as the Dumaru family of Trojans have had screen-capture capability for years. What has changed is the ability of the programs to sift through meaningless screen interactions and capture only those exchanges that reveal sensitive log-in information, according to Hubbard.

      “Weve seen a server within the neighborhood of 1,200 account [screen captures] uploaded for a single bank. Of all the images captured, most only captured keystrokes when the banking site was accessed,” Hubbard said.

      Websense discovers a new Trojan program that can do screen captures about every two weeks, he said.

      The Anti-Phishing Working Group identified 170 new pieces of keylogging software, which it terms “crimeware,” in recent weeks. Only 1 or 2 percent of those programs have screen-capture features, said Dan Jevans, chairman of the APWG.

      /zimages/1/28571.gifCheck out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

      Paul F. Roberts
      Paul F. Roberts

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.