As part of this week’s ‘Get Safe Online’ campaign, Trusteer today issued a warning that fraudulent phone calls are increasing in popularity amongst the criminal community to commit ID theft and that everyone needs to be on their guard to avoid falling victim – on or offline. One possible use for these bogus ‘bank’ calls is to utilise personal identification information stolen using malware to give fraudsters credibility as they collect the missing information required to ‘pull off’ their scams.
"The phenomenon of stealing data using one channel such as the web and using it in a different channel or context such as social engineering attacks is often overlooked", said Amit Klein, CTO of Trusteer. "Trusteer has found that data collected by Man in the Browser attacks can be used for other purposes than automated transaction fraud. Defending against the new wave of hybrid attacks requires both technology to detect MitB malware and vigilance from the users of online services."
Traditional financial malware fraud starts off by identifying the targeted bank and learning how their online banking service functions. Once fraudsters understand the online banking flows and security processes, a fraudulent scheme is designed and the corresponding malware attack is configured. Lastly, bank clients are infected with the malware and fraud starts its execution sequence.
Other forms of financial malware fraud work in reverse – First malware is placed on victims’ machines and malware logs online activity and banking credentials, fraudsters use credential data fished from malware logs to access online banking sites and perpetrate fraud. Trusteer Research has even identified fraudsters selling Zeus malware logs in the open market – the going price is between 1$ to 60cents per 1GB.?
However, the problem with this method is, in many cases, the data collected by the malware is insufficient to commit the actual fraud:
§ The one time password (OTP) authentication credentials originally collected are no longer valid
§ Banks require Transaction Signing to transfer money
§ Additional authentication data is required by the bank when logging in from a new IP address?
‘Professional caller services can be used by fraudsters to obtain the missing data required to complete a successful online fraud. A forum advertisement, discovered by Trusteer, offers a phone service with professional callers, fluent in English and European languages, who can impersonate male and female, as well as old and young voices. As with any business the service states its regular ‘operating hours’ as available during American and European working hours. The price is a rather reasonable 10$ per call. These criminals were offering calls to private customers, banks, shops, post offices and any other organisations according to the customers’ specific requirements. They’ll even prepare the spoof phone numbers to accept calls in case victims should want to call back for any reason. Trusteer’s additional security verification reveals that the group has been operational since 2009.?
Although the actual caller’s scripts are not shared in the forum advertisement we can imagine scripts used to collect the missing data would look something like:?
Step 1: Caller Establishing Credibility
The caller would use data collected by the malware to gain credibility, for example the caller will ask "Are you John Smith, living at their address, with credit card number ending with 2345?"
Step 2: Caller Collect Missing Data?Once the caller has established credibility, they will go on to collect:
a) The SMS OTP - for example "We have just sent you an SMS with an OTP so we can make sure you are John Smith, can you please read it for me?"
b) Collect any other additional authentication information, for example "For verification, can you please give me the last four digits of your SSN?"
c) They can even get the user to generate a transaction signing code with fraudulent payee and amount information, for example "We need to calibrate your transaction signing reader so could you please enter the following details online and then tell us what happens."?
Amit Klein, CTO of Trusteer said, "While everyone’s attention is focused on protecting themselves in the ‘virtual’ world, they’re still very much at risk back here in the ‘real’ world. Fraudsters are turning to phone call services in an endeavour to trick people into disclosing their confidential information, sourcing professional callers to impersonate representatives from financial organisations. The sad truth is that it is actually far easier to perpetrate social engineering over the phone than many realise."? Klein concludes "It’s rather disturbing how professional the group’s marketing is. It claims to have extensive experience working with bank customers, banks and shops. It even highlights their financial expertise, bragging that in the majority of cases they complete bank transfers and transactions."?
For individuals, Trusteer advises they:
1 make sure to use up-to-date anti-malware solutions, especially any recommended by their bank, to prevent data theft in the first instance;
2 treat all unsolicited phone calls with caution, irrespective of any validation information the caller may offer;
3 use contact numbers provided by the bank, not the caller, to verify the authenticity of the contact.?
About Trusteer: Trusteer offers solutions for financial institutions, home users, and businesses. Financial institutions use Trusteer services to secure their customers' browsers from financial malware attacks and fraudulent websites. Trusteer allows financial institutions to proactively protect against attacks that target customers directly. In addition, Trusteer allows financial institutions to receive immediate alerts, and to report whenever a new threat is launched against them or their customers. Using Trusteer, financial institutions can investigate new zero day threats, suspicious computers, and reconnected infected computers.
Don't have a current membership with ContactCenterWorld.com?
become a member and connect with the rest of the Contact Center Industry at ContactCenterWorld.com here
Forum Profile
Job Title:
(Display this on the Forum)
Company:
(Display this on the Forum)
Neither the Administrators of these forums, or the Moderators participating, are responsible for the privacy practices of any user. Remember that all information that is disclosed in these areas becomes public information and you should exercise caution when deciding to share any of your personal information. Any user who finds material posted by another user objectionable is encouraged to contact us via e-mail. We are authorized by you to remove or modify any data submitted by you to these forums for any reason we feel constitutes a violation of our policies, whether stated, implied or not.
This site may contain links to other web sites and files. We have no control over the content and can not ensure it will not be offensive or objectionable. We will, however, remove links to material that we feel is inappropriate as we become aware of them.
By pressing the "Agree" button, you agree that you, the user, are 13 years of age or over. You are fully responsible for any information or file supplied by this user. You also agree that you will not post any copyrighted material that is not owned by yourself or the owners of these forums. In your use of these forums, you agree that you will not post any information which is vulgar, harassing, hateful, threatening, invading of others privacy, sexually oriented, or violates any laws.
If you do agree with the rules and policies stated in this agreement, and meet the criteria stated herein, proceed to press the "Agree" button below, otherwise press "Cancel".
If you have any questions about this privacy statement or the use of these forums, you can contact the forum administrator at: rajw@contactcenterworld.com