Gang steals 550,000 bank account details
By Stuart Turton
Posted on 3 Nov 2008 at 09:56
A single criminal gang has used a Trojan to gather login information for 300,000 online bank accounts and 250,000 credit card accounts, according to a new report.
The information was harvested over the last three years using the Sinowal Trojan, which is typically found on gambling or porn sites, according to RSA FraudAction Research Lab, the security firm that discovered the attack.
The worm triggers when a user visits one of 2,700 banking URLs, and initiates a HTML injection attack that creates legitimate looking fields on the website, prompting the user to enter a national insurance number, or other piece of personal information. This information is then uploaded to a server, before ultimately being sold on.
"This may be one of the most pervasive and advanced pieces of crimeware ever created by fraudsters," reports RSA on its blog. "Only rarely do we come across crimeware that has been continually stealing and collecting personal information and payment card data, and compromising bank accounts as far back as 2006.
"In addition to its longevity, Sinowal has also been evolving at a dramatic pace - its rate of attacks spiked upwards from March through September of this year," the blog adds.
The lab claims the Sinowal Trojan was once associated with the infamous Russian Business Network, but may now be under the control of a new gang. However, it is still going strong and the lab claims it has stolen the login information for 100,000 online bank accounts in the last six months alone.
From around the web
advertisement
- Chrome's shine getting lost in translation
- BytePac: the cardboard hard disk enclosure
- How tech loosens our grip on reality
- Hokum watch: Safer Internet Day
- Why I'm deleting Adobe from my PC
- Prepare to be patronised: it's Safer Internet Day
- Dear Sony, Samsung and every other tech company in the world: stop trying to be Apple
- Will Apple's Final Cut Pro X update placate the pros?
- Smartr Contacts for iPhone review
- Switching to Office 365's Outlook Web App
- Why virtualisation hasn't slowed the growth of data
- How to make Google AdWords work for your business
- The curse of sloppily written software
- Paying for your crimes with Bitcoin
- Behind the scenes: tech support for Formula 1
- The security risk of fat fingers
- Why Windows Phone 7 isn't quite ready for business
- When will Microsoft stop fiddling with Windows 8?
- Flash down the pan?
- Metro Style apps vs desktop applications
advertisement
