sexta-feira, 21 de novembro de 2014

Intel and Europol together to combat cibercrime


An MOU between Intel Security Firm and Europol, will see the two combine resources and Expertise in combating cybercrime, in an already porous battle line. As cybercriminals advance their techniques and expertise, it is paramount that all those on the receiving end stage a united front or perish one at a time.

Europol received a boost in its fight against cybercrime after McAfee signed an MOU to help shore up Europol’s security operations. The MOU will see the two combine resources and expertise in forming a solid defense against cybercrime, in an already porous battle line.

McAfee, acquired by Intel Security group in 2010, will offer technical support to Europol in addition to participating in joint cybercrime operations and sharing non-operational data on cybercrime.  With its innovative approach to internet security and vast intelligence on Global threats, Intel security will be an important strategic ally to EU’s top cops.

“Cybercrime has advanced to a degree that no one entity can combat it alone,” said Raj Samani, chief technology officer for EMEA at Intel Security and special advisor to the EUROPOL Cybercrime Centre on Internet Security . “I’m excited to work with the excellent team Europol and contribute expertise so that we can together to effectively address the cybercrime problem.”

High profile attacks such as the JPMorgan, Whitehouse and the Target clearly shows that cybercriminals are advancing their techniques and expertise, leaving law enforcement agencies entirely clueless in all occasions. In such an environment, it is paramount that all those on the receiving end including law enforcement agencies stage a united front, a fact Troels Oerting, Head of the EC3 acknowledged when welcoming Intel on board. “Today we add the resources of Intel Security to our list of capabilities dedicated to protecting our digital lives. This task cannot be done by law enforcement alone, and requires a much broader approach,” said Oerting.

Apparently, McAfee and Europol have partnered on cybercrime before andthe MOU signed on Wednesday was only meant to formalize and expand their co-operation.“Intel Security has assisted the European Cybercrime Centre (EC3) in the past and, with the signing of this MOU, our cooperation will continue to the benefit of all law-abiding users of the Internet and to the disadvantage of cybercriminals,” said Oerting in a press release.

In the past, Cyber security firms have only cooperated with law enforcement agencies through informal arrangements. The new MOU between Intel Security and Europol marks a new era of cooperation in fighting cybercrime, with more cyber security firms expected to come on board in the coming days.

EU state countries have also shown unprecedented cooperation in the war against cybercrime Currently, over 30 states have ratified the Council of Europe’s Convention on Cybercrime, an international treaty that seeks to harmonize cybercrime Laws among party states. The treaty will also establish a cross-border and cybercrime investigation unit to respond on cyber threats on a real time basis.

Europol is a cross border agency that helps combat international crimes in the European Union. Its cybercrime unit, European Cybercrime Unit (EC3), located in The Hague offers technical supports to other EU states cybercrime units. EC3, formed last year, relies Europol’s extensive network to help EU states investigate and comber cybercrime, including state backed cyber-espionages attacks that are currently ruling the cyberspace.

quinta-feira, 20 de novembro de 2014

Brazilian Cibercrime picture


Trend Micro has published a new study on black cyber-markets focusing on product and services offered on the Brazilian underground.

Trend Micro has published a new interesting report on the underground cyber-markets, this is a third study focused on the Brazilian cyber-underground offer, the previous ones analyzed Russian and Chinese marketplaces.

The new study, exactly like previous analysis, describes a thriving marketplace where cyber criminals proposes their services and products to criminal crews that instead of creating their own attack tools from scratch could benefit of the competitive offer. The study reports the principal solution and services proposed to the crooks in a model of sale known as crime-as-a-service that is able to attract new actors in the cyber arena.

A first data that immediately catches the attacention of the experts is decrease of prices recently offered, this is a further element of attractive for criminals that look to the cyber crime with increasing interest.

“The barriers to launching cybercrime have decreased. Toolkits are becoming more available and cheaper; some are even offered free of charge. Prices are lower and features are richer. Underground forums are thriving worldwide, particularly in Russia, China, and Brazil. These have become popular means to sell products and services to cybercriminals in the said countries. Cybercriminals are also making use of the Deep Web to sell products and services outside the indexed or searchable World Wide Web, making their online “shops” harder for law enforcement to find and take down.” states the ‘The Brazilian Underground Market’ report.

Another element of distinction between the Brazilian underground and the Russian and Chinese ones, is the availability of training services, for this reason the Brazilian underground ecosystem is also considered as the market for cybercriminal Wannabes.

“What distinguishes the Brazilian underground from others is the fact that it also offers training services for cybercriminal wannabes,” according to the whitepaper. “Cybercriminals in Brazil particularly offer FUD (fully undetectable) crypter programming and fraud training by selling how-to videos and providing support services via Skype. Anyone who is Internet savvy and has basic computing knowledge and skill can avail of training services to become cybercriminals. How-to videos and forums where they can exchange information with peers abound underground. Several trainers offer services as well. They even offer support when training ends.”

The Brasilian cyber criminals seem to be more ruthless in the use of media platforms like Facebook, YouTube, Twitter, Skype, and WhatsApp, differently from Russian and Chinese players that “hide in the Deep Web and use tools that ordinary users do not such as Internet Relay Chat (IRC) channels”

For several years, Brazil has been known for the offer of banking Trojans, many malware were designed by Brazilian which targeted internal banking users and that implemented several techniques to steal victims’
credentials. Brazil ranks second worldwide in terms of online banking fraud and malware infection, on a global scale it accounts for almost 9% of the total number of online-banking malicious code that compromised

Brazilian underground banking malware

Banking Trojan source codes are sold for around US$386 each, the offer allows buyers to modify their codes according their needs, they can obfuscate strings, customize the composition of payloads and add crypters and other solution to evade the detection. Another product very popular are  Bolware kits and toolkits used to create bolware that are offered for around US$155, the applications offered by cybercriminals are user-friendly and implements an easy to use control panel for monitoring and managing infections and malicious activities.

Brazilian underground banking malware prices

The Brazilian underground also offers a bank fraud courses for aspiring cyber-criminals, the courses are very articulated and propose detailed information for beginners to the criminal activities. The courses starts presenting the fraud workflow and tools necessary to arrange a cyber fraud. Some coursed are arranged in modules that propose interesting information on the illegal practices to cybercriminal wannabes that can acquire also interactive guides and practical exercises (e.g., simulating attacks). A 10-module corse for example is offered for US$468, the operators also offer updates and a Skype contact service.

According to the author of the study on the Brazilian underground market, Trend Micro Senior Threat Researcher Fernando Merces, several factors have contributed to the growth of cyber-criminal activity in the country like limited resources assigned to law enforcement and the existence of a flexible underground market.

“For example, Brazil has a lack of concrete laws and limited law enforcement agency resources that address cybercrime in the country,” he noted. “Additionally, the technological and consumer landscape in Brazil, which has a 50% Internet penetration rate, and a 69% credit card penetration rate, has made the country all too appealing for cybercriminals. However, another factor may have also contributed to Brazilian cybercrime: the existence of a flexible underground market with different offerings, ranging from banking Trojan development to online fraud training. The latter is highly notable as this is the most unique item in the market, which may not be found in other underground markets.” explained Merces in a blog post. 

The report details prices and products for many other products and services, including Credit card credentials and number generators, SMS-spamming services and  phishing pages for popular banks.

Let me close the post with a meaningful statement from the author of the study that explain how is simple today to become a dangerous cyber criminals with limited resources.

“In Brazil, it’s possible to start a new career in cybercrime armed with only US$500,” Merces blogged. “Would-be cybercriminals are supported and helped by tools, forums, and experts from the dark side of the Internet. These bad guys do not fear the authorities and their groups get bigger in a short span of time.”

Let me suggest you to read the full report published by Trend Micro, it is full of interesting data.

Pierluigi Paganini

(Security Affairs –  Brazilian underground, cybercrime)

terça-feira, 18 de novembro de 2014

Cibercrime use Bash Vulnerability

Cyber criminals are using new malware variants by exploiting GNU Bash vulnerability referred to asShellShock (CVE-2014-6271) in order to infect embedded devices running BusyBox software, according to a researcher.

A new variant of "Bashlitemalware targeting devices running BusyBox software was spotted by the researchers at Trend Micro shortly after the public disclosure of the ShellShock vulnerability.

BusyBox provides set of command line utilities that are specifically designed to run in constrained embedded environments. At compile time, different capabilities can be left out, reducing the size of the binaries, and efforts are made to make them memory efficient. This makes the software an excellent candidate for use in consumer electronics devices, which seem to have been the items of interest in this case.

The malware variant, detected as ELF_BASHLITE.A (ELF_FLOODER.W), when executed on victim's machine, scans compromised networks for devices such as routers and Android phones running BusyBox to brute force logins through a preset list of usernames and passwords.

The variant would then run a command to download and run bin.sh and bin2.sh scripts to gain control over Busybox systems once a connection was established. Therefore, this newer version of Bashlite is designed not only to identify systems running BusyBox, but also to hijack them.
"Remote attackers can possibly maximize their control on affected devices by deploying other components or malicious software into the system depending on their motive," threat response engineer at Trend Micro, Rhena Inocencio wrote on a blog post.
"As such, a remote attacker can issue commands or download other files on the devices thus compromising its security."
Miscreants attempted to log in using a predefined list of usernames which include 'root', 'admin' and 'support' and common and default list of passwords such as 'root,' 'admin,' '12345,' 'pass,' 'password,' '123456' and so on.

Trend Micro's Inocencio urged users to change their default usernames and passwords in order to keep them on the safer side, and also to disable remote shells, if possible, to avoid its exploitation.

Bashlite malware includes the payload of the ShellShock exploit code and threat actors have used this critical ShellShock Bash command vulnerability (CVE-2014-6271) to build botnets from hijacked devices, launchdistributed denial-of-service (DDoS) attacks, and target network attached storage boxes among other exploits.

The Critical ShellShock Bash bug was disclosed on September 24 and by September 30 security firms estimated that attacks using the exploit could top 1 billion, and more than 1000 organizations patched the ShellShock bug as fixes became available.

EASE, the DHS concept of self-repairing networks


by Pierluigi Paganini on November 18th, 2014
EASE network defense

The Department of Homeland Security is working with industry to the EASE concept, a self-repairing systems able to avoid the interruption of the operations.

The Department of Homeland Security is working on a new generation of self-repairing network that is able to be resilient to cyber offensives and continue operations in case of attack.
Enterprise Automated Security Environment (EASE), is the name of the project conducted by the DHS with industry for the development of an automated cyber defense system, as explained by Philip Quade, chief operating officer of the National Security Agency’s information assurance directorate, to the Nextgov.
Resiliency is considered by cyber security experts an essential characteristic of future networks, cyber attacks are becoming even more sophisticated and frequent and computer systems have to be improved to remain operative despite the ongoing offensive.
In the recent weeks, several attacks hit government networks, causing data breaches and temporarily  shut down of the infrastructure, as happened in the attacks against the White House, the U.S. Postal Service and the National Weather Service.
cyber attacks Department of Homeland EASE system
The goal is the realization of a network of computers that is able to avoid disrupting activities and protect sensitive information.
Actually, government entities have deployed a series of internal controls to detect the early attacks and quickly recover from potential cyber attack. EASE is an ambitious project, despite it is in a very early stage, the Department of Homeland is spending a great effort into its realization.
The EASE project will integrate the ongoing project related to the network surveillance program conducted by the US Government that allocated $6 billion to support it.
“EASE is an evolving concept aimed at further automating the detection and prevention of cyber intrusions against federal government networks by creating a suite of technologies to augment existing methods,” DHS spokesman S.Y. Lee said in an email.
The surveillance program, dubbed “continuous diagnostics and mitigation,” is under development by US authorities to realize a real-time monitoring of all federal networks for threats.
“Homeland Security is leading its development, in coordination with private sector partners, as part of a long-term effort to strengthen existing cyber defense capabilities through better interoperability and shared situational awareness, real-time response, and the protection of privacy, civil rights and civil liberties,” Lee added.
The DHS’official anyway remarked that EASE is still an idea in an embryonic, but it is also a concrete need for the country and for this reason the US Government will continue to support it and any other program that could improve its cyber capabilities.

Suspected Wirelurker iOS Malware Creators Arrested in China

Suspected Wirelurker iOS Malware Creators Arrested in China
It’s been almost two weeks since the WireLurker malware existence was revealed for the first time, andChinese authorities have arrested three suspects who are allegedly the authors of the Mac- and iOS-based malware that may have infected as many as hundreds of thousands of Apple users.

The Beijing Bureau of Public security has announced the arrest of three suspects charged with distributing the WireLurker malware through a popular Chinese third-party online app store. The authorities also say the website that was responsible for spreading the malware has also been shut down.

"WireLurker" malware was originally discovered earlier this month by security firm Palo Alto Networks targeting Apple users in China. The malware appeared as the first malicious software program that has ability to penetrate the iPhone's strict software controls. The main concern to worry about this threat was its ability to attack non-jailbroken iOS devices.

Once a device infected with the malware, the virus could download the malicious and unapproved apps, which are designed to steal information, from the third-party app stores and, if it detects an iOS device connected through the USB slot, it would install the malicious apps on the device as well.
"This malware is under active development and its creator’s ultimate goal is not yet clear," the researchers wrote in a report [PDF]. "The ultimate goal of the WireLurker attacks is not completely clear. The functionality and infrastructure allows the attacker to collect significant amounts of information from a large number of Chinese iOS and Mac OS systems, but none of the information points to a specific motive. We believe WireLurker has not yet revealed its full functionality."
Unlike most iPhone bug, WireLurker malware has ability to install even on non-jailbroken iOS devices because the malware authors have used enterprise certificates to sign the apps. Apple has since revoked these cryptographic certificates used to sign WireLurker, and blocked all the apps signed with it. Palo Alto estimated that hundreds of thousands of users installed the malicious apps.

China appears to have taken the threat very seriously and within two weeks arrested three individuals who are believed to be the creators of the malicious software.

Although, there is not much details available about the arrest as the Bureau has simply posted a short notification on its Sina Weibo, a Chinese micro blogging service.

But according to the Chinese authorities, the three suspects are identified as "Chen," "Lee" and "Wang," who are suspected of manufacturing and distributing the malicious program "for illegal profit," and that the Chinese authorities have been helped in the investigation by researchers from Chinese AV company Qihoo 360.

Windows Phone possible hack.

Operators of the XDA-developers forum explained how it is possible to hack Windows Phone 8.1 to run any app package in any Program directory.

XDA-developers have discovered a new vulnerability in latest Microsoft OS Windows Phone 8.1 that could easily be exploited by attackers to compromise a Nokia Lumia phone running it.
The XDA Developers member known as DJAmol has discovered a vulnerability in the OS Windows Phone 8.1 that allows hackers to run arbitrary applications with other user’s privileges and edit the registry.
The XDA developers forum has already reported the security issue to the Microsoft, as explained by the operators of the forum the vulnerability could give higher privileges to the attackers if tried using a First Party Application, rather a third party app.
“There is a possibility to run any app package in any Program directory. Can be possible run homebrew app in second party and first party directory. Important thing is that app run’s with the reserved capabilies of the targeted directory. Such as “SECOND PARTY APPLICATION” capabilities and “FIRST PARTY APPLICATION” capabilities.” XDA-developers state in a blog post.
The hackers explained that simply by replacing the contents of a trusted OEM app that has been transferred over to the SD card, the attacker’s app will inherit the privileges of the legitimate one. Once transferred the malicious app, the attacker have to delete the existing directory and create a new one with the same name as the original App.
windows phone 8.1-1
In this way the third party registry editor app will gain full access to the Info and Settings in the app itself. The XDA-developers provided a detailed description of the hack on Windows Phone 8.1 in their post, below the basis steps to execute.
  • Develop your own application package and deploy it on the target device.
  • Install an application from the Window Phone app Store, for example “Glance Background Beta”.
  • Delete all folders under the targeted directory of the installed app, in this example proposed by the hackers, Glance background [Install, NI, TempInstall, TempNI, XBF etc].
  • Copy the contents of your own deployed package in the targeted directory, replacing the “Program Files” of the installed app with your package files.
  • Launch the App that will run in OEM (Glance Background beta) directory with the privileges of the targeted App.
The hack on the Windows Phone 8.1 is very easy to implement, but it has not yet escalated to a full interop unlock, as the applications that are allowed to be moved to the SD card have limited access.
“Doees this mean that lumia phones can be-are interop unlocked?” asked the user matgras
“May be or may not be. I’ve not research yet on it.  Does this mean that lumia phones can be-are interop unlocked?
Those methods also work on any OEM Device, not specific for the Lumia.”
Stay tuned for more information on the case that are expected from Microsoft.

domingo, 16 de novembro de 2014

MORE ATM HAKED



EmailPrint
Two little known Tennessee men used factory default passcode to dupe ATM machines into giving more cash in an 18 months hacking spree cut short by Secret Service.  The money minting operations proves how low-tech street criminals poses a threat to poorly configured and serviced ATMs all over the world.

A recent shocker in the tech world revealed that over 80% of ATM’s use outdated Windows XP which run out commercial support years ago. Just to show how ATMs machines are vulnerable to low-tech street crime, two little know  Tennessee men, Khaled Abdel Fattah and his accomplice Chris Folad,  went on an ATM hacking spree in Nashville, netting over $400,000 hard cash in their 18 moths expedition.

Note that this was a not typical hack employing sophisticated banking malwares to steal money. Instead the two used a sequence of key combinations on the Keypad to configure the ATM into “Operator mode” and crack the cash dispensers. Once on operator’s modes the ATM was configured to dispense $20 for $1 requested. For example a $20 withdrawal would dispense $400 hard cash.

Fattah and his accomplice now face an array of computer frauds charges following their short-live money minting operations in Nashville. “Fattah and an associate named Chris Folad are facing 30 counts of computer fraud and conspiracy, after a Secret Service investigation uncovered evidence that the men had essentially robbed the cash machines using nothing more than the keypad,” reported wired in a blog.

Technically, ATM can be configured into operators mode using passcode initial provided the manufacturer.  Once on operator’s mode, the operator is able to configure how the ATM dispenses cash including the denomination loaded on the cartridges. In this case, Fatah was a former employee of ATM firm and all he needed was to key in the factory-set passcode.

The fraud was first discovered by the business owner who realized an abnormality in cash flows in one of ATM kiosks visited by the duo. He informed the secret service who analyzed surveillance footage, tracked and nailed Fattah and his accomplice.

“They were little kiosk ATMs, like you would find in a business or a convenience store,” says Greg Mays, assistant special agent in charge of the US Secret Service’s Nashville office. “I believe the businesses noticed there was a problem when the machine was running out of money.”

Fortunately, Fattah and his friend conducted their operation in the full glare of security cameras, they also used their real debit cards making it easy for Secret Service to trail and net them.

Exploits of this nature are common in the Tech world, but majority of the incidences go unreported by banks and other financial institutions who fear the possibility of a bank run. The problems lies with the factory resent passcode given by the ATM vendor and usually written on ATM manual. A majority of the small business owners fail to reset the default code on a new machine or when an employee leaves.  In reality, the code should be changed frequently and maintained within a small circle of employees if necessary.

In a similar ATM hack in 2005, fraudsters discovered the factory set passcode of Tranax and Triton ATMs, was freely available online. They went viral hacking every available Machine prompting Triton and Tranax to reprogram their machine and force operators to change the passcode on first use.

In another incidence a 14-year old boy in Winnipeg followed an instruction manual to crack the operator’s passcode to access a Bank of Montreal ATM in June this year. The boy notified the bank to change its

sábado, 15 de novembro de 2014

More ATM haked

Cybercrime expert explains anyone with technical knowledge, a malware and the help of an insider could easily hack an ATM machine.

A RM100 chip, specific technical knowledge and a free malware obtained over the Internet is all the necessary to hack Automated Teller Machines (ATMs), this is the opinion of a cybercrime expert, which released an exclusive interview to the FMT (freemalaysiatoday.com).

The cybercrime expert was invited to report in regard to a recent hacking case of 17 ATMs, a Latin American gang of cyber criminals was able to hack and steal millions of dollars from the automated teller machines in Malaysia.

The hackers steal more than $1.2 million from ATMs of at least 17 bank branches belonging to United Overseas Bank, Affin Bank, Al Rajhi Bank and Bank of Islam were reportedly hacked into by the Latin American gang.

The Closed-circuit television (CCTV) footage from the banks showed that 2-3 Latin American men entered and withdraw money from these targeted ATM machines.

“What you need is a mastermind, a RM100 computer chip and possibly a bank ‘insider’ to execute the attacks.” he said.

The 17 ATM hacks must be a warning for the banking industry that according to the expert is loosing field in the fight against cybercrime.

“Banks should look into their security seriously, and not just for the sake of compliance.”“This mentality has to be changed to build security in the DNA of the bank.”

RM100 ATM hacking

A little information is needed to the attacker, the knowledge of the targeted system could be enough to compromise a banking ATM, all this information  typically provided by insiders.

“He (the hacker) will know where the locks and connections are, the model of the machine, the level of security and the version of the operating system.” explained the expert.

The expert also pointed out the roles of the guys captured by the surveillance cameras at the bank

“The guys caught on the CCTV are not the actual criminals.” “It’s like the ‘monkey see, monkey do’ situation. They can be shown what is supposed to be done without the need for any technical knowledge. They probably do not even know what they are doing.”

According to the expert, the hack of an ATM machine could be very easy using malware easy to find in the underground, a security expert has  no problem to wreak havoc on the actual banking system.

“It is a simple attack as there are many free malware available online. And it is definitely something that the bank has to seriously think about.”

Based on his experience in the sector, the expert highlighted the wrong approach of the banking industry in the protection of ATMs machines, in many cases these machines run out dates OSs, lack of patch management or they are poorly configured.

The expert is very controversial with financial institutions, he explicitly refers to the results of a series of penetration tests conducted against banking systems that succeeded to breach the

“The bank I worked for was not happy that we breached the system after doing a hacking” he said.  “It’s either they wanted to ensure that we couldn’t find anything, or, they will hire incompetent people who will not find anything.”

The results of the penetration testing session demonstrate the presence of several weaknesses in the banking systems, in many cases the ATMs were running on outdated operating systems like Windows XP.

“Banks have been taking things for granted because nothing like this has ever happened before.” the expert added.“They depended heavily on the CCTV and in some locations, they do not even have security guards.

The experts involved in the test also discovered many other serious flaws in the ATM, lack of encryption could expose sensitive data to tampering advantaging the hack of these machines with a malware based attack.

“It is also because of the lack of encryption technology such as the Public Key Infrastructure (PKI). “If the PKI was implemented, it wouldn’t have happened.” he added

Pierluigi Paganini

(Security Affairs – ATM hacking, RM100 computer chip)

Seminário sobre privacidade vai agitar São Paulo

http://www.emersonwendt.com.br/2014/10/evento-v-seminario-de-protecao.html?m=1

quinta-feira, 13 de novembro de 2014

Workshop segurança cibernética é noticia


Segurança da informação será tema de workshop no Rio de Janeiro
Últimas Notícias - Notícias
TER, 11 DE NOVEMBRO DE 2014 10:30 ESCRITO POR AGÊNCIA GESTÃO CT&I

O avanço das ameaças no ciberespaço e as formas de se proteger no meio virtual serão termas do workshop “Segurança Cibernética para as novas Infraestruturas Inteligentes”, a ser realizado nesta quinta-feira (13) no pólo de laboratórios do Instituto Nacional de Metrologia, Qualidade e Tecnologia (Inmetro), no município de Duque de Caxias (RJ). A programação, que inclui painéis e sessões técnicas, tem como proposta incentivar um debate sobre a importância do desenvolvimento de ferramentas de segurança.
Promovido pelo Inmetro e seu equivalente nos Estados Unidos, o National Institute of Standarts and Technology (NIST), o encontro abordará assuntos como o controle e monitoramento via rede de serviços como água e energia elétrica, por exemplo. As duas entidades já desenvolveram pesquisas conjuntas em áreas estratégicas, como calibração e biocombustíveis, entre outras.

Para saber mais detalhes sobre as inscrições, além da programação completa, acesse o site do workshop neste link.

(Agência Gestão CT&I,

Cibercrime using keyloggers

Trend Micro issued a research paper on operations behind Predator Pain and Limitless keyloggers, both of which are easily obtainable from underground.

Cybercriminals ordinary use malicious code to steal money from victims, the number of malware available in the criminal ecosystem is continuously growing, their level of sophistication and cost are extremely variable. Thinking of banking malware, Zeus and SpyEye are probably the most popular, but represent the tip of the iceberg, in the underground it is possible to acquire low-priced malware that anyway can ensure to fraudsters substantial gains.
Security experts are aware that all these malicious code, if in the “right” hands, can bring in an astounding amount of money and create huge losses to the collectivity.
Security experts at TrendMicro have published an interesting paper on the operations behind Predator Pain and Limitless keyloggers, two low-priced ($40 or less), off-the-shelf keyloggers/RATs that are easy to acquire on the underground forums. The researchers have analyzed both Predator Pain and Limitless keyloggers for only a few months, discovering a surprising reality.
Predator Pain and Limitless screeshot
Predator Pain and Limitless screeshot 2
Let’s start from the economic perspective, the cost of these RATs is  $40 or less, but the malware implements similar capabilities with many other data stealer.
“Predator Pain and Limitless have the capability to steal a lot of information and exfiltrate them back to the cybercriminals. These are off-the-shelf tools and are easily obtainable for US$40 or less in underground forums orwebsites run by their creators.”  “Attackers, after obtaining access to infected computers and the credentials stored in them, sit on a gold mine of information that they can use for various criminal and fraudulent activities,” the researchers explain in a whitepaper.
Data provided by the Commercial Crime Bureau of Hong Kong Police Force reveals that cybercriminals using the above malware against small and medium-sized businesses in Hong Kong have earned more than $75 million in the first half 2014. These data are alarming, if we compare these losses to the economic impact of the Zeus Botnet as explained in the paper:
“Consider: this means that cybercriminals in a single city, within six-months, equaled all the losses from Zbot up to the present,” Trend Micro senior threat researcher Ryan Flores pointed out. “Unlike Zeus, Predator Pain and Limitless are relatively simple keyloggers. They indiscriminately steal web credentials and mail client credentials, as well as capturing keystrokes and screen captures. The output is human readable, which is good if you are managing a few infected machines only, but the design doesn’t scale well when there are a lot of infected machines and logs involved,” he explained.
Predator Pain and Limitless graph
“In fact, in Hong Kong alone, the estimated loss resulting from corporate email fraud has increased 491% from 2012 to 2013 and 180% from 2013 to 2014. As of June 2014, the total reported loss amounted to HK$565.5 million (approximately US$73 million).”
Predator Pain and Limitless Comparison
The use of off-the-shelf keyloggers/RATs like Predator Pain and Limitless doesn’t impact the illicit activities of criminal crews, in many cases, crooks prefer to invest more time and effort instead of using automated malware that results anyway more expensive.

“The tools these fraudsters use are not advanced. Combined, clever targeting, patience, cunning and simple keyloggers have netted these cybercriminals large sums of money,” Flores said. “These highlight that cybercrime activities are dependent not only on the sophistication of the tools used, but on how well organized the entire scheme is. A sophisticated, well-designed scam can net its operators significant sums of money, as seen here.”

The monitoring on several Predator Pain and Limitless attacks allowed the experts to track the used of these tools, in particular the findings revealed that a significant portion of operators was involved in utilizing the following:

The 419 or Nigerian scams through easy-to-deploy, high-volume attacks
Scammed corporate emails that convince recipients to deposit payment to specially crafted accounts
419 scammers are considered within more lucrative activities on a large scale that benefit of the malware to hit exclusively SMBs. SMBs are more exposed to external attacks due to the lack of an efficient security posture and dedicated IT security staff.

“SMBs may not be involved in multimillion-dollar deals, but they do conduct transactions worth tens to hundreds of thousands of dollars,” the researchers noted. “As the world relies more and more on Web services (e.g., webmail), all it will take to ruin a business is a single compromised online account.”

The common attack scenario based on these malicious code sstart sending out classic phishing emails to publicly listed email addresses. The attackers attach the keylogger to the email, once the victims install it the malware silently steal user data, including system screenshots, keystrokes, browser-cached account credentials, and sends information back to the command and control servers via email, FTP, or Web panel (PHP).

“Attackers, after obtaining access to infected computers and the credentials stored in them, sit on a gold mine of information that they can use for various criminal and fraudulent activities. Successfully stealing online banking credentials can lead to financial theft. Some of the stolen information provide attackers more leverage for subsequent attacks. They can, for instance, get their hands on actual emails and use these to “hijack” ongoing transactions between their chosen victims and their clients” states the paper referring the postinfection activities.

The report highlights that stolen data could be used later for further attacks against victims and could be sold in the underground to other criminal organization, personal data and sensitive information are a precious commodity in the underground.

The most scaring aspect of the analysis made by researchers on the use of Predator Pain and Limitless is that criminal gangs are targeting SMBs (small and medium-sized businesses) considered vulnerable targets by the gangs that aim to realize rapid gains exploiting the lack of awareness of general IT security best practices.

The “Predator Pain and Limitless When Cybercrime Turns into Cyberspying” is another excellent analysis conducted by the researchers at TrendMicro, don’t miss this report.

Pierluigi Paganini

(Security Affairs –  Predator Pain and Limitless keyloggers, keyloggers/RAT)

Share it please ...Tweet about this on TwitterShare on Google+Share on FacebookShare on LinkedInPin on PinterestShare on RedditEmail this to someoneShare on StumbleUpon
Share this:
EmailTwitter15PrintLinkedIn21Facebook11More
November 13, 2014
« Previous
View Full Site
Proudly powered by WordPress

EM 2026, CIBERSEGURANÇA DEIXOU DE SER UM PROBLEMA TÉCNICO A transição da defesa tática para a liderança estratégica em infraestruturas crít...