Close
  • Latest News
  • Artificial Intelligence
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity
    • Networking

    Zeus Criminals Launch DDoS Attacks to Hide Fraudulent Wire Transfers

    By
    Fahmida Y. Rashid
    -
    December 1, 2011
    Share
    Facebook
    Twitter
    Linkedin

      The Federal Bureau of Investigation has warned of an elaborate spear-phishing campaign that wires money out of victims’ accounts under the cover of a distributed denial-of-service attack against the bank.

      The new spear-phishing campaign masquerades as emails from the National Automated Clearing House Assocation (NACHA) and downloads a variant of the Zeus banking Trojan onto the victim’s computer, theFBI Denver Cyber Squad said in its warning issued Nov. 23.

      The malware steals the user’s online banking credentials and launches a DDoS attack on the financial institution to hide the fact that it is also transferring money out of user accounts. The DDoS attacks may also make it difficult for the financial institution to stop or reverse the transfers even if they are detected in time.

      The email informs the recipient that there was a problem with a transaction at their bank and it was not processed. By clicking on the link in the email, the recipient is directed to a Website that downloads the Zeus variant called “Gameover” to the recipient’s computer, the FBI warned. Gameover is capable of keylogging to steal banking credentials as well as defeating several forms of two-factor authentication mechanisms the banks may be employing.

      The new spear-phishing campaign involves “personal and business bank accounts, financial institutions, money mules and jewelry stores,” according to the warning.

      Attackers are becoming increasingly smart and stealthy in their DDoS methods, Mike Paquette, chief strategy officer at Corero Network Security, told eWEEK. While a brute-force or flooding type of DDoS attack can be relatively easy to identify, it requires high-performance and sophisticated real-time analysis to recognize and block attack traffic while simultaneously allowing legitimate traffic to pass, according to Paquette.

      Application layer attacks, such as the one posed by the recent Apache Killer, are “more insidious” and require the financial institution to have a thorough understanding of the typical behaviors and actions of their actual customers, he said.

      Paquette suggested that financial institutions should automate DDoS defense to create user profiles to identify suspicious traffic, much in the same way automated credit card fraud-detection technologies look for unusual spending activity.

      A portion of the wire transfers is being transmitted directly to high-end jewelry stores, according to the warning. The criminals contact a jeweler looking for precious stones and luxury watches. They promise to wire the money directly to the jeweler’s account and someone will come to pick up the merchandise.

      Once the fraudulent wire transfers are complete, a money mule comes to the actual store to pick up thousands of dollars of goods, the FBI said. Even though the transaction is reversed when the fraud is discovered, the jeweler is unable to recover the goods.

      DDoS attacks against high-profile targets are generally perpetuated by intelligent, determined and persistent adversaries, and this “new breed” of attackers will switch to different sources and methods as necessary, Paquette said. Therefore, advance preparation is key to being able to respond to these DDoS attacks effectively, Paquette said. A response plan lists the steps the institution should take during a DDoS attack.

      Hiding malicious activity by distracting the defenders with a DDoS attack is not new. The perpetrators who breached Sony’s PlayStation Network and Sony Online Entertainment services earlier this year appear to have taken advantage of the fact that the entertainment giant’s IT staff was busy trying to contain the DDoS attacks that had been launched by the Anonymous hacktivists.

      Institutions shouldn’t rely on just the Internet service providers to be able to mitigate the DDoS attack, but should deploy technology in-house to serve as the front-line defense against both flooding type and application-layer DDoS attacks, according to Paquette. DDoS mitigation tools need to be deployed alongside monitoring services so that organizations can rapidly identify and react to sustained attacks.

      “Continuous and automated monitoring is required in order to recognize an attack, sound the alarm and initiate the response plan,” Paquette said.

      Fahmida Y. Rashid
      Get the Free Newsletter!
      Subscribe to Daily Tech Insider for top news, trends & analysis
      This email address is invalid.
      Get the Free Newsletter!
      Subscribe to Daily Tech Insider for top news, trends & analysis
      This email address is invalid.

      MOST POPULAR ARTICLES

      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Applications

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      IT Management

      Intuit’s Nhung Ho on AI for the...

      James Maguire - May 13, 2022 0
      I spoke with Nhung Ho, Vice President of AI at Intuit, about adoption of AI in the small and medium-sized business market, and how...
      Read more
      Applications

      Kyndryl’s Nicolas Sekkaki on Handling AI and...

      James Maguire - November 9, 2022 0
      I spoke with Nicolas Sekkaki, Group Practice Leader for Applications, Data and AI at Kyndryl, about how companies can boost both their AI and...
      Read more
      Cloud

      IGEL CEO Jed Ayres on Edge and...

      James Maguire - June 14, 2022 0
      I spoke with Jed Ayres, CEO of IGEL, about the endpoint sector, and an open source OS for the cloud; we also spoke about...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2022 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×