Feeds

New ZeuS-based Trojan leeches cash from cloud-based payrolls

Adds phishing mules to employee roster

Reducing the cost and complexity of web vulnerability management

Cybercrooks have forged a ZeuS-based Trojan that targets cloud-based payroll service providers.

ZeuS, a favourite tool for financially motivated cybercrooks, has provided a straightforward way to harvest online banking credentials for years. A new attack, detected by transaction security firm Trusteer, shows that crooks are going up the food chain.

Trusteer researchers have captured a ZeuS configuration that targets Ceridian, a Canadian human resources and payroll services provider. The ZeuS-based Trojan works by capturing a screenshot of the payroll services web page when a malware-infected PC is used to visit the site. This information is uploaded, allowing crooks to obtain the user ID, password, company number and the icon selected by the user for the image-based authentication system – enough information to siphon funds from compromised accounts into those controlled by money mules, as explained in a blog post here.

Trusteer reckons crooks are targeting the small cloud service provider in order to get around the tougher problem of how to bypass industrial strength security controls that are typically maintained by larger businesses. Cloud services can be accessed using unmanaged devices that are typically less secure and more vulnerable to infection by ZeuS-style financial malware.

The financial losses associated with this type of attack are potentially huge. For example, last August cyberthieves reportedly stole $217,000 from the Metropolitan Entertainment & Convention Authority (MECA) after compromising its payroll system and adding money mules as employees. A MECA worker reportedly fell for a phishing email that allowed crooks to steal access credentials to the organisation's payroll system.

Hitting payroll providers is certainly far more lucrative than targeting individual consumers, according to Trusteer, which predicts a growth in this type of attack as a result. ®

Reducing the cost and complexity of web vulnerability management

More from The Register

next story
Wanna keep your data for 1,000 YEARS? No? Hard luck, HDS wants you to anyway
Combine Blu-ray and M-DISC and you get this monster
US boffins demo 'twisted radio' mux
OAM takes wireless signals to 32 Gbps
Apple flops out 2FA for iCloud in bid to stop future nude selfie leaks
Millions of 4chan users howl with laughter as Cupertino slams stable door
No biggie: EMC's XtremIO firmware upgrade 'will wipe data'
But it'll have no impact and will be seamless, we're told
Students playing with impressive racks? Yes, it's cluster comp time
The most comprehensive coverage the world has ever seen. Ever
Run little spreadsheet, run! IBM's Watson is coming to gobble you up
Big Blue's big super's big appetite for big data in big clouds for big analytics
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.