Feeds

Viruses, phishing, and trojans for profit

Malware is big money

Using blade systems to cut costs and sharpen efficiencies

Customised trojans, for a price

If there's one thing we've learned, just about anything is available for a price.

Dmitri Alperovitch from CipherTrust gave an excellent presentation at Virus Bulletin on "phishing trojan creation toolkits". His talk was about how it's now possible to go out and purchase a fully customised Trojan horse for phishing purposes, one that can inject new fields into a legitimate web page.

In other words, the average Joe Criminal can go out and purchase a toolkit that can create a targeted, fully customised trojan horse capable of evading the detection of anti-virus software, and then use it to steal money from innocent people. There's still the issue of getting this trojan in the right place, but let's take this one step at a time.

The example Alperovitch showed was quite advanced, capable of numerous features like support for encryption and two-factor authentication that allows a less sophisticated cyber criminal to make just the right kind of trojan. Set up the required features and click the button that says compile.

I found it all quite shocking, to be honest - I did not know how far these trojan toolkits have come, or how much it can lower the bar. One of the greatest security fears of any organisation is (or should be) targeted trojans, because of their capability to steal virtually any information inside an organisation and remain undetected for some time. I won't take the liberty of mentioning some of the toolkits here, which range from $100 to $5500.

What can these trojans help steal? Money, for starters. Phishing works because most people can't identify a fake website. Let's also consider another use for them. It's easy to imagine a targeted trojan running on a payroll manager's computer inside a Fortune 500 company, logging keystrokes, taking screenshots, and responding to commands from someone on the other side of the world – or someone just next door. Add me to your payroll, please. A bit far-fetched? Hopefully your organisation has the proper policies and procedures in place to prevent this.

When the early reports of hackers teaming up with organised crime first surfaced, I'll admit I was skeptical. I found it hard to imagine a geek, albeit a criminal one, meeting up with the mob in a dark alley somewhere and plotting their next attack. But we're talking big money now, millions and tens of millions of dollars in some of the trojan-phishing-botnet-spam scams. Maybe much more.

The link to organised crime and traditional low-tech criminals for cyber criminals is more likely one of pure necessity – converting "virtual money" stolen from individuals and companies still has to be converted to real money, and that's where traditional crime rings and money laundering come into play.

Law enforcement is pretty good at investigating the low-tech end result of high-tech crime, and that's where they should continue to focus. Rather than turn police officers into hackers, they should continue to work with (and pay) security people to unravel the technical capabilities. Let me put some emphasis on paying security folks for their hard work.

The smart choice: opportunity from uncertainty

More from The Register

next story
Yorkshire cops fail to grasp principle behind BT Fon Wi-Fi network
'Prevent people that are passing by to hook up to your network', pleads plod
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
NEW, SINISTER web tracking tech fingerprints your computer by making it draw
Have you been on YouPorn lately, perhaps? White House website?
LibreSSL RNG bug fix: What's all the forking fuss about, ask devs
Blow to bit-spitter 'tis but a flesh wound, claim team
Black Hat anti-Tor talk smashed by lawyers' wrecking ball
Unmasking hidden users is too hot for Carnegie-Mellon
Attackers raid SWISS BANKS with DNS and malware bombs
'Retefe' trojan uses clever spin on old attacks to grant total control of bank accounts
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
Don't look, Snowden: Security biz chases Tails with zero-day flaws alert
Exodus vows not to sell secrets of whistleblower's favorite OS
prev story

Whitepapers

Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.