the evolution of ecrime and the remote banking channels

28
The evolution of eCrime and the remote banking channels Presentation to the RHUL MSc Information Security Summer School 9 September 2013 Dom Lucas

Upload: clinton-burnett

Post on 30-Dec-2015

32 views

Category:

Documents


0 download

DESCRIPTION

The evolution of eCrime and the remote banking channels. Presentation to the RHUL MSc Information Security Summer School 9 September 2013 Dom Lucas. Overview. Setting the Scene Attacks & Exploits Monetising the attack The bigger picture. Setting the Scene. What is eCrime?. - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: The evolution of eCrime and the remote banking channels

The evolution of eCrime and the remote banking channels

Presentation to the RHUL MSc Information Security Summer School

9 September 2013

Dom Lucas

Page 2: The evolution of eCrime and the remote banking channels

Overview

Setting the Scene

Attacks & Exploits

Monetising the attack

The bigger picture

Page 3: The evolution of eCrime and the remote banking channels

Setting the Scene

Page 4: The evolution of eCrime and the remote banking channels

What is eCrime?

Page 5: The evolution of eCrime and the remote banking channels

Organised Crime

Page 6: The evolution of eCrime and the remote banking channels

Remote banking?

Page 7: The evolution of eCrime and the remote banking channels

What is being attacked?

Page 8: The evolution of eCrime and the remote banking channels

Why?

In economic terms

Wider Market Base.

Greater ROI.

Cost/Benefit Model.

In criminal terms

I rob banks ‘cos that’s where the money is

Willie Sutton c1930

Page 9: The evolution of eCrime and the remote banking channels

Attacks & Exploits

Page 10: The evolution of eCrime and the remote banking channels

Phishing

Page 11: The evolution of eCrime and the remote banking channels

Phishing Explained

1. Attacker creates / hijacks website

2. Phishing email sent

3. Victim directed to phishing site

4. Phished Credentials forwarded to Drop server

5. Creds forwarded to phisher

6. Creds traded on online forums

7. Phishers use credentials to access genuine accounts

Page 12: The evolution of eCrime and the remote banking channels

Phishing evolved

MITM/Real-time Phishing Capture & use victim 2-FA pass code in real time thus defeating

multi factor authentication.

HTML form attachment Doesn't require a phishing a site and so evades traditional phishing

takedown.

Vhishing & Smishing Use of traditional social engineering techniques to gather credentials

Use of VOIP technology to spoof & evade detection

Page 13: The evolution of eCrime and the remote banking channels

Malware

Page 14: The evolution of eCrime and the remote banking channels

Malware

ZEUS

Spyeye

Citadel

Carberp

ICE IX

Shylock

Page 15: The evolution of eCrime and the remote banking channels

Attack vectors

www.XXX.com

Page 16: The evolution of eCrime and the remote banking channels

Monetising the attack

Page 17: The evolution of eCrime and the remote banking channels

Beneficiaries/Money Mules

Continues to be the Bottleneck

lots of credentials not enough mule

accounts

Money Mule categories

The professionals

The unsuspecting/duped

Developments

Pre-Paid card accounts- lack of KYC

Fake online businesses

International Payments (SEPA)

International fraud payments to mule

accounts across the EU.

Job offer

We have found your resume at Monster.com

and would like to

suggest you a "Transfer manager" vacancy.

We have thoroughly studied your resume and

are happy to inform you that your skills

completely meet our requirements for this

position.

Our company buy, sell, and exchange digital

currencies, like E-gold and E-bullion.

Page 18: The evolution of eCrime and the remote banking channels

Putting it all together

Page 19: The evolution of eCrime and the remote banking channels

Crime as a Service

Page 20: The evolution of eCrime and the remote banking channels

Op HighRoller

Customised Zeus / Spyeye variant.

Automated.

Checked balance.

High net-worth accounts >e200,000.

Targeted over 60 institutions

Global network of mules.

Page 21: The evolution of eCrime and the remote banking channels

The Wider Picture

Page 22: The evolution of eCrime and the remote banking channels

Global View

Page 23: The evolution of eCrime and the remote banking channels

Future Challenges

Page 24: The evolution of eCrime and the remote banking channels

Things to think about

Page 25: The evolution of eCrime and the remote banking channels

The next generation….

Page 26: The evolution of eCrime and the remote banking channels

Don’t underestimate the adversary

Page 27: The evolution of eCrime and the remote banking channels

Maintain situational awareness

Page 28: The evolution of eCrime and the remote banking channels

Questions?