Original URL: http://www.theregister.co.uk/2007/10/19/return_of_trojan_bayrob/
Miscreants have unleashed a new strain of a sophisticated Trojan that targets eBay users by feeding them spoofed web pages containing fraudulent information about high-ticket purchases, The Register has learned. It has already contributed to an $8,600 loss by one eBay member.
The Trojan installs a scaled-down webserver on an infected machine that masquerades as eBay and several third-party destinations frequently used to sniff out fraudulent offerings, including Carfax.com, Autocheck.com and Escrow.com.
When a victim browses to one of these sites, the webserver creates a parallel universe of sorts, in which the victim sees counterfeit pages designed to counter fraud protection mechanisms offered by eBay and third-party sites.
"To think that somehow they got software on their system that managed to spoof all the validation sites - that's a shit-scary story," said Roger Thompson, a researcher at Exploit Prevention Labs (http://www.explabs.com/) who specializes in web-based attacks. "It's fiendishly clever."
The malware was found on the machine of one eBay Motors user who recently lost $8,650 after trying to buy a 2005 Jeep Liberty advertised for 10 days on the site. Customer representatives have refused to cover the theft because, they said, the transaction was made outside of eBay.
Shortly after making the offer, the victim received a notification in the My Messages (http://pages.ebay.com/help/myebay/my-messages.html) section of her eBay account telling her she had won the auction. eBay has long cautioned users not to rely on notifications unless they appear in this official section.
The malware installed on the victim's machine caused her browser to display a counterfeit version of just such a message. Had she used a non-infected computer to access her account, no such message would have appeared.
"There's no reason to suspect it's fraud until it's too late," said the Ohio-based user, who agreed to tell her story on the condition her identity was not revealed. The Register was able to verify the scam by confirming details with eBay and by reviewing screenshots, emails and files pulled from her machine.
The malware appears to be a reworking of Trojan.Bayrob, which first came to light (http://www.theregister.com/2007/03/06/ebay_trojan/) in early March when researchers from Symantec wrote reports here (http://www.symantec.com/enterprise/security_response/weblog/2007/03/ebay_motors_scam.html) and here (http://www.symantec.com/enterprise/security_response/weblog/2007/03/ebay_motor_scam_update.html).
It arrives in an attachment to an email responding to a bid and installs a local proxy server that redirects traffic bound for eBay. The proxy, according to Symantec, spoofs sensitive pages on eBay, including the "ask a question" messaging feature for online auctions. The Trojan also inflates the user feedback score of the purported buyer, according to Symantec.
In the intervening seven months, the Trojan has been updated so that, among other things, traffic bound for sites such as Carfax and nine other addresses maintained by third-party companies will also be redirected. This helps thwart victims who try to independently confirm details fed on the falsified eBay pages.
eBay spokeswoman Nichola Sharpe says the company's security team has forwarded samples of the new strain to anti-virus companies so they can add it to the updates they send to customers.
When the Ohio victim used her infected PC to get a history of the Jeep from Carfax, she was told the vehicle was in California, a detail that was consistent with what scammers were telling her. Using a clean computer to access the same information shows the Jeep is located in Pennsylvania.
Seeing no reason to doubt the authenticity of the auction, the victim paid $8,650 on October 4 using a bank-to-bank transfer, a payment method that is approved by eBay. She has yet to receive delivery of the Jeep, and the purported seller has since become unreachable.
Although eBay Motors promises to protect (http://pages.motors.ebay.com/services/purchase-protection.html) purchases up to $20,000 against fraud, the company is refusing to cover the costs of the Ohio victim. "Items purchased outside of eBay are not covered, including those bought directly from a seller," a customer representative wrote in an email to the victim.
The victim, a college-educated stay-at-home mother, said she kept on top of her Windows updates, ran security software from Symantec and was careful not to fall for the ploy of phishers. eBay's security team says she got infected after clicking on the email attachment sent in response to her bid. She said it never occurred to her that a bid she made on eBay would leave her open to an attack that would completely compromise her system.
So she has opted to close down her eBay and PayPal accounts and vowed never again to do business with the company.
I don't have a right to be on there because I'm not knowledgeable about everything [criminals] are pulling there these days, she said. "I assumed I was purchasing this through eBay so my guard was down. As high-tech as this was, I don't know what I would have done differently." ®
If you have intelligence about Trojan.Bayrob or other scams targeting eBay, please contact Dan Goodin using this link (http://forms.theregister.co.uk/mail_author/?story_url=/2007/10/19/return_of_trojan_bayrob/).
eBay breaks bread with luxury goods firms (21 July 2008)
http://www.theregister.co.uk/2008/07/21/ebay_counterfeit_summit/
PayPal ambushes users with mystery Skype charges (13 June 2008)
http://www.theregister.co.uk/2008/06/13/paypal_skype_glitch_reports/
French court fines eBay for sale of counterfeit handbags (5 June 2008)
http://www.theregister.co.uk/2008/06/05/ebay_counterfeit_ruling/
'Secure' PayPal page is... you guessed it (16 May 2008)
http://www.theregister.co.uk/2008/05/16/paypal_page_succumbs_to_xss/
Notorious eBay hacker arrested in Romania (18 April 2008)
http://www.theregister.co.uk/2008/04/18/vladuz_arrested/
eBay scripting trick used to boost seller ratings (18 March 2008)
http://www.theregister.co.uk/2008/03/18/ebay_scripting_malfeasance/
PayPal buys Israeli security firm (28 January 2008)
http://www.theregister.co.uk/2008/01/28/paypal_buys_fraud_firm/
New Trojan preys on commercial banking customers (17 December 2007)
http://www.theregister.co.uk/2007/12/17/prg_bank_trojan/
Grisoft acquires LinkScanner (5 December 2007)
http://www.channelregister.co.uk/2007/12/05/grisoft_buys_epl/
Tracking down the Ron Paul spam botnet (5 December 2007)
http://www.channelregister.co.uk/2007/12/05/ron_paul_botnet_explored/
Canadian loses $20K in phony eBay sale (4 December 2007)
http://www.theregister.co.uk/2007/12/04/fraudulent_ebay_motors_sale/
Reported malfunction in PayPal Security Key (28 November 2007)
http://www.channelregister.co.uk/2007/11/28/paypal_security_key_bug/
Trojan spreads using PI wiretapping scare (20 November 2007)
http://www.theregister.co.uk/2007/11/20/bogus_wiretap_trojan_scam/
eBay Trojan morphs to snare motor victims (15 November 2007)
http://www.channelregister.co.uk/2007/11/15/trojan_bayrob_morphs/
eBay glitch wipes out 11 year-old account without a trace (12 November 2007)
http://www.theregister.co.uk/2007/11/12/ebay_glitches/
Botmaster owns up to 250,000 zombie PCs (9 November 2007)
http://www.theregister.co.uk/2007/11/09/botmaster_to_plea_guilty/
Woman admits fleecing shopping network of more than $412,000 (30 October 2007)
http://www.theregister.co.uk/2007/10/30/website_fraud_guilty_plea/
World's most gullible supermarket chain falls victim to online scam (29 October 2007)
http://www.theregister.co.uk/2007/10/29/supermarket_online_scam/
Print beats net for fraud (29 October 2007)
http://www.theregister.co.uk/2007/10/29/ftc_study/
UK mobiles not worth stealing (26 October 2007)
http://www.theregister.co.uk/2007/10/26/stolen_phones_blocked/
Online sales of stolen gear prompt call to list serial numbers (26 October 2007)
http://www.theregister.co.uk/2007/10/26/us_ebay_crime_law/
eBay employee 'torpedos' fraud trial (25 October 2007)
http://www.theregister.co.uk/2007/10/25/ebay_employee_torpedoes_trial/
eBay forum mysteriously leaks account details on 1,200 users (25 September 2007)
http://www.theregister.co.uk/2007/09/25/ebay_account_details_published/
Uber-hacker Max Vision misses the killswitch (18 September 2007)
http://www.theregister.co.uk/2007/09/18/max_butler_affidavit/
Serial eBay fraudster jailed for two years (22 August 2007)
http://www.theregister.co.uk/2007/08/22/serial_ebay_fraudster_jailed/
Anatomy of an eBay scam (21 March 2007)
http://www.theregister.co.uk/2007/03/21/ebay_fraud_anatomy/
Once again, 'Vladuz' impales eBay defenses (13 March 2007)
http://www.theregister.co.uk/2007/03/13/vlad_impales_ebay/
eBay goes hacker hunting in Romania (8 March 2007)
http://www.theregister.co.uk/2007/03/08/who_is_vladuz/
eBay users targeted by advanced Trojan (6 March 2007)
http://www.theregister.co.uk/2007/03/06/ebay_trojan/
© Copyright 2008