New Trojan gives criminals full-service bank theft
Security experts agree that cyber-criminals are getting better, but a new Trojan takes things to a whole new level.
The URLzone Trojan, identified by researchers at Web filtering vendor Finjan Software earlier this month, represents "the next generation of bank Trojans," said Yuval Ben-Itzhak, Finjan's chief technology officer.
After it infected about 6,400 computer users last month, the Trojan was clearing about €12,000 (US$1,750) per day. That puts it on track to rake in as much as €7.3 million annually.
Criminals installed the Trojan by luring visitors to infected Web sites and leveraging a variety of PC software flaws. They managed to infect about 7.5 percent of the 90,000 computers they attacked before Finjan got access to their command-and-control server, the company said.
More widespread Trojans such as Zeus and Clampi have been siphoning millions of dollars per day out of banks by stealing victim's online credentials and then moving money to unsuspecting "money mules" who then transfer the cash offshore. These mules are often recruited from job sites such as Monster.com and they typically believe they're doing legitimate payroll work for overseas companies, and not organized criminal enterprises. Once they send the stolen money offshore, they can be the ones who are held accountable for the loss.
But URLzone is even more sophisticated than its predecessors, Ben-Itzhak said.
Its sophisticated user interface lets the bad guys set some controls that help keep fraud detection systems at bay. From a central server, they can, for example, set the system to ensure that the account's balance never drops below zero; they can pre-set the system to make a series of small withdrawals that will appear unsuspicious; and the software will change the way the victim's banking page is displayed so the true transactions don't get displayed.
"Basically they say, 'I will steal from you €5,000, but I want to make sure at least 5 percent will remain in your balance,'" Ben-Itzhak said.
IDG News Service
Sign up for ITworld's Daily newsletter
Follow ITworld on Twitter @IT_world
On Twitter now
Finjan Software
Powered by Twitter
Esther Schindler
If the comments are ugly, the code is ugly
claird
SVG a graphics format for 21st century
pasmith
Take Chrome OS for a test spin
Sandra Henry-Stocker
Solaris Tip: Have Your Files Changed Since Installation?
jfruh
Android fragments vs. the iPhone monolith
mikelgan
What Gizmodo missed about the Pro WX Wireless USB disk drive
Sidekick: The Good News & the Bad News
Either way you look at it Microsoft Data Center management did not follow standards or best practices in this failure. In which case it makes me wonder more about the outsourcing of corporate data much less personal data.
- mburton325
Join the conversation here
Quick, practical advice for IT pros. Made fresh daily.
Want to cash in on your IT savvy? Send your tip to tips@itworld.com. If we post it, we'll send you a $25 Amazon e-gift card.














This is going to start sounding very familiar
to anyone attending any of the Agricultural Colleges out there -- taking tips from the context of industrialized farming. "Controlled harvesting of your cash cows"...not bad
remaining undetected can be a definite challenge for some people and these people seem to have pulled it off.