EDITION:GLOBALNORTH AMERICACENTRAL & SOUTH AMERICAUK & IRELANDEUROPEMIDDLE EAST & AFRICA AUSTRALIA & NEW ZEALANDASIA
ICCW
OVER 122,000 MEMBERS

The Global Association for Contact Center Best Practices & Networking

CHANNELS: Agent Zone Benchmarking CRM HR Outsourcing Performance Quality Technology Telecom Training Workforce Management

Site Map
About this Site
Contact Us


 
 FEATURED SUPPLIERS
on ContactCenterWorld.com this week:

Blue Ocean Contact Centers


Top Ranking Performers Conferences 2010


TopPlace2Work


Allnone


OPEX Hosting


Global Benchmarking Study of Top Performers




Business Systems UK Ltd





Click on the company name for more details!



 




Financial Malware is Attacking US Banks Using Visa and MasterCard Hoax

London, 14th July 2010 –Trusteer, a provider of secure browsing services, today announced that the Zeus (Zbot) financial malware is targeting online banking customers of 15 leading US financial institutions by exploiting two trusted credit card security programs. After users have initiated a secure online banking session, the Zeus Trojan injects into the browser a facsimile of the familiar Verified by Visa and MasterCard SecureCode enrollment screen. It then prompts users to enter their social security number, credit or debit card number, expiration date, and PIN or CSV code.

The information gathered by Zeus is used by fraudsters to commit ‘card not present’ transactions with retailers that employ Verified by Visa and SecureCode protection. This stolen data allows criminals to impersonate their victims and register with these programs to ensure fraudulent transactions elude fraud detection systems.

Trusteer used its Flashlight remote fraud investigation and mitigation service to discover this new in-session phishing attack, and collect Zeus configurations and code samples from infected computers. This version of Zeus attempts to trick online banking customers into surrendering their personal and credit/debit card data by claiming new FDIC rules require that they enroll in the Verified by Visa / MasterCard SecureCode program to protect their accounts.

"While some users may become suspicious when prompted to enter their credit/debit card information as part of the online banking login process, this attack uses the familiar Visa and MasterCard online fraud prevention programs to make the request appear legitimate," said Amit Klein, CTO of Trusteer and head of the company’s research organization. "Fortunately, online banking customers protected by Trusteer Rapport are not vulnerable to this attack since it blocks HTML injection and prevents Zeus from presenting the fraudulent enrollment request."

Zeus, which is also known as Zbot, WSNPOEM, NTOS and PRG, is the most prevalent banking malware platform for online fraud , and has been licensed by numerous criminal organizations. It infects PCs, waits for the user to log onto a list of targeted banks and financial institutions, and then steals their credentials which are sent to a remote server in real time. It can also modify, in a user’s browser, the genuine web pages from a bank’s web servers to ask for personal information such as payment card number and PIN, one time passwords, etc.

Anti malware detection of Zeus has a poor track record. In a 2009 report based on information gathered from 3 million desktops in North America and the UK Trusteer found that the majority of Zeus infections occur on antivirus protected machines. Specifically, Trusteer found that among Zeus infected machines 55% had up-to-date Antivirus protection installed. The population of machines infected with Zeus is enormous -- one in every 100 computers according to Trusteer research.


Related News
Trusteer Detects Spread of New Polymorphic Version of Zeus Online Banking
Malware Analysis and Remediation for Financial Institutions
Trusteer Says Its Prediction On Adobe PDF Attack Has Come True
Keylogger Sophistication Rising as Criminals Look for New Sources of Card Fraud Revenue Says Trusteer
Microsoft's Emergency Out-of-Band Update is Good News for Internet Users
TJX Hacker Sentencing Signals the Need for Customer e-Banking Security Vigilance says Trusteer CEO

About Trusteer:
Trusteer offers solutions for financial institutions, home users, and businesses. Financial institutions use Trusteer services to secure their customers' browsers from financial malware attacks and fraudulent websites. Trusteer allows financial institutions to proactively protect against attacks that target customers directly. In addition, Trusteer allows financial institutions to receive immediate alerts, and to report whenever a new threat is launched against them or their customers. Using Trusteer, financial institutions can investigate new zero day threats, suspicious computers, and reconnected infected computers.

More Editorial from Trusteer
Trusteer Detects Spread of New Polymorphic Version of Zeus Online Banking
Trusteer Says Its Prediction On Adobe PDF Attack Has Come True
Keylogger Sophistication Rising as Criminals Look for New Sources of Card Fraud Revenue Says Trusteer
Microsoft's Emergency Out-of-Band Update is Good News for Internet Users
TJX Hacker Sentencing Signals the Need for Customer e-Banking Security Vigilance says Trusteer CEO
Malware Analysis and Remediation for Financial Institutions

Date Published: Thursday, July 15, 2010
Printer Friendly Version Printer friendly version
 Recommend to a friend
 Bookmark & Share

Login

Username: 
Password: 
Remember Password

Forgot Password?
Become a Member






Ad

OnBrand Advertisement

LATEST MEMBERS

Over 122,417 Members in the contact center, help desk, CRM industry
View members' directory









-Back To Top-

| Request Information from CRM & Contact Center Suppliers | About ContactCenterWorld |
| Advertise CRM & Contact Center Solutions | Link to this site |
| Submit CRM and Contact Center Content | Contact Us | Privacy Policy |
| Recommend this site to other CRM & Contact Center Professionals | Disclaimer |

©ContactCenterWorld.com 1999-2010
The Global Support Organization For Contact Center Professionals & the place for information on:
Click To Call, Computer Telephony Integration (CTI), Contact Center & Customer Service Associations, Contact Center & Help Desk Certification, Contact Center Analytics, Contact Center Automation, Contact Center Compliance, Contact Center Consultancy, Contact Center Design, Contact Center Furniture, Contact Center Location, Contact Center Management, Contact Center Message Boards, Contact Center Software, Contact Center Trends, Contact Management, Cost per Call, CRM