Tuesday, April 21, 2009

FBI, DoD Officials Recognized for Cyber Security Contributions

William Jackson writes on GCN.com:

Two government officials were recognized this morning at the RSA Security conference for their contributions to cybersecurity.

Robert Lentz, deputy secretary for cybersecurity at the Defense Department, received the award for excellence in the field of security practices for his work during eight years at DOD in implementing the Common Access Card program and improving acquisitions, among other work.

FBI Special Supervisory Agency J. Keith Mularski, who helped to lead a two-year investigation of the Dark Market cybercriminal forum that resulted in 56 arrests last year, received the award for excellence in the field of public policy.

More here.

Thursday, October 16, 2008

FBI Says Dark Market Sting Netted 56 Arrests

Robert McMillan writes on PC World:

A two-year undercover FBI sting operation targeting online fraudsters has netted 56 arrests and prevented millions of dollars in economic losses, the FBI said Thursday.

The FBI said it had infiltrated online "carder" forums hosted on the DarkMarket.ws Web site, which was widely used by online scammers to buy and sell stolen credit card numbers, other financial information, and even the devices used to make fake banking cards. Before it was shut down earlier this month, the Web site had registered more than 2,500 members.

The FBI ran its sting in cooperation with the U.K.'s Serious Organized Crime Agency and authorities in Turkey and Germany. "The arrests this week in the U.K. are a good demonstration of the coordination taking place today between the FBI, the Serious Organized Crime Agency... and other law enforcement agencies around the globe," FBI Cyber Division Assistant Director Shawn Henry said Thursday in a statement.

In addition to the drawing the 56 arrests, the sting helped the FBI seize compromised accounts and prevent the loss of about US$70 million in fraud, the FBI said. It has also generated new leads that are being tracked down by international law enforcement.

More here.

Thursday, August 20, 2009

Bot-Brokering: It's All About Infecting, Selling Big Batches of Bots

Kelly Jackson Higgins writes on Dark Reading:

Researchers at Cisco recently got a rare glimpse of the inner workings of the botnet underworld after going undercover and meeting an actual botmaster online: the botmaster, who ran a botnet that had infected dozens of machines at a Cisco customer site, said his main job is to compromise a few thousand machines and then sell them off in bulk.

He told a Cisco researcher posing as a fellow botmaster that the market rate for a bot is between 10 cents to 25 cents per machine, and that he recently made $800 off of a sale of 10,000 bots.

But that rate is likely a moving target, says Joe Dallatore, senior manager in Cisco's security research and operations group. "At this point we have a snapshot [in time]" of the botnet market rate, Dallatore says. "There is an economy for these things, and it changes over time this is a form of commerce, with supply and demand."

And the botmaster isn't out to perform identity theft -- just bot-brokering. "He was not in the business of using information [on the bots]. Just in creating bots and selling them to someone else," Dallatore says.

More here.

Note: Cisco seems to be a bit late to the game -- this model of "pay-per-load" is quite well-known to most of the security research constituency, and has been around literally for years. -ferg

Friday, March 02, 2007

Inside Wall Street's Computer Meltdown

Brian Braiker writes on Newsweek.com:

Were the computer glitches that exacerbated the downward trajectory of the market Tuesday illustrative of the dark side—the Achilles heel—of the markets' move toward more electronic trading? Or were they bumps along the learning curve—"growing pains," as one trader described them—that will ultimately lead to smoother trading?

"On Tuesday at around 2 p.m., the market's extraordinarily heavy trading volume caused a delay in our trading system," explains a spokesperson for Dow Jones & Co., the media company that manages the index of 30 blue-chip stocks. For 70 minutes, a slow data feed to the Dow Jones industrial average (DJIA) calculator meant that traders were working off a slightly outdated set of numbers.

When the error was caught, the system was switched to a backup server that immediately readjusted the figures—sending numbers across the board into a free-fall plunge of 178 points in a single minute.

More here.

Tuesday, October 28, 2008

Economic Crisis May Be Boon For Cybercriminals

Kelly Jackson Higgins writes on Dark Reading:

One industry sector is actually happy about the current state of the global economy: cybercriminals.

"One thing we've seen is financially based cybercrime is recession-proof," says Darren Mott, supervisory special agent for the FBI's Cyber Division. "With [this] changing economy, the only thing that changes is the way they go about obtaining their information."

Organized cybercrime has already begun capitalizing on the global financial crisis, cybercrime experts say, with targeted phishing attacks on customers whose banks have folded, and attacks that scam consumers who may be shopping less online, but are now spending more time at home. With fewer business and consumer targets available, the bad guys are redirecting their efforts to adapt to the market. For example, credit cards are out; debit cards are in.

More here.

Thursday, November 29, 2007

Cyber Crime Glimpse: Making $1M a Month

Kelly Jackson Higgins writes on Dark Reading's "I, Shadow":

If software vulnerabilities are costing the U.S. $180 billion per year as David Price says in his new book, "Geekconomics: The Real Cost of Insecure Software," just how much are the bad guys making?

Price, director of the Monterey Group and a SANS course instructor, says we really don't know. But there are some shocking examples of just how lucrative cybercrime can be, Price says.

Take the infamous 76service.com, which was run by two enterprising criminals who call themselves 76 and Exoric. The two (who are now apparently on the lam) cleared a cool one million dollars per month in a scheme modeled after portfolio investments, Price says.

They sold access to infected PCs (think bots), but apparently didn't do any of the data-stealing themselves, he says. "The 76service sold all these 'owned' machines in what they called a 'project,'" Rice explains. The buyer would harvest any valuable data off the machine, and sell that information to the black market.

More here.

Friday, March 02, 2007

Police Try MySpace to Nab Bank Robber

An AP newswire article, via SFGate.com, reports that:

A brazen bank robber with nothing but a baseball cap and dark sunglasses hiding his face is one of the latest members of the social-networking Web site MySpace, and he wants to meet "more bank tellers so that I can continue my crime spree!!!"

Even though MySpace is popular with teenagers, Fort Smith police Sgt. Jarrard Copeland created the profile Friday hoping someone will recognize the man estimated to be about 60 and suspected in four bank robberies across Arkansas.

"We figure that might be one way to get this photo outside of the market," he said.

Amid a backdrop of $100 bills and a song "Citizens on Patrol" from the movie "Police Academy," the profile displays several photos from a Feb. 22 robbery at a U.S. Bank branch in Alma in which the suspect wore a blue jacket with "FBI" lettering on the left front and a blue ball cap.

More here.

Thursday, January 10, 2008

Quote of the Day: Tim Wilson

"Clearly, we're not just seeing the rise of a new security threat here, but the emergence of an entire competitive market. We're seeing price competition, product differentiation, and the creation of niche markets."

- Tim Wilson, writing on Dark Reading.


Wednesday, September 28, 2005

Scams Targeting Online Games: Old Phish With Fresh Bait

Via Netcraft.

Are phishing crews paying more attention to virtual worlds? Phishing attacks on massively multiplayer online role-playing games (MMORPGs) have been around since at least 2002, and perhaps earlier. But some observers of online games say the growing market for virtual currency and player accounts may be attracting fresh attention from phishing scams, which are mass-mailing "bait" e-mails seeking to capture gamers' account logins.

Phishing attacks most commonly target banks, credit card companies and payment sites such as Paypal. This year phishers have expanded their target list to include smaller regional banks and credit unions. While phishing attacks on online games aren't new, they may represent a logical area of expansion for these scams, given the growing value of player accounts, the youthful demographics of online gaming, and a recent influx of new players due to the popularity of World of Warcraft.

A recent phishing attack targeting users of EVE Online was reported by Terra Nova, a blog that follows trends in virtual worlds. The bait email purports to be from the game's security team, investigating unusual account activity and sending victims to a spoof site at a server in Spain.

Early phishes on MMORPGs date to 2002, when Dark Age of Camelot began warning users about bait emails, while other early efforts targeted Everquest. In January Netcraft received reports of a phishing attack seeking to steal user account details for Runescape, a free virtual world popular with younger gamers.