Gang steals 550,000 bank account details
Posted on 3 Nov 2008 at 09:56
A single criminal gang has used a Trojan to gather login information for 300,000 online bank accounts and 250,000 credit card accounts, according to a new report.
The information was harvested over the last three years using the Sinowal Trojan, which is typically found on gambling or porn sites, according to RSA FraudAction Research Lab, the security firm that discovered the attack.
The worm triggers when a user visits one of 2,700 banking URLs, and initiates a HTML injection attack that creates legitimate looking fields on the website, prompting the user to enter a national insurance number, or other piece of personal information. This information is then uploaded to a server, before ultimately being sold on.
"This may be one of the most pervasive and advanced pieces of crimeware ever created by fraudsters," reports RSA on its blog. "Only rarely do we come across crimeware that has been continually stealing and collecting personal information and payment card data, and compromising bank accounts as far back as 2006.
"In addition to its longevity, Sinowal has also been evolving at a dramatic pace - its rate of attacks spiked upwards from March through September of this year," the blog adds.
The lab claims the Sinowal Trojan was once associated with the infamous Russian Business Network, but may now be under the control of a new gang. However, it is still going strong and the lab claims it has stolen the login information for 100,000 online bank accounts in the last six months alone.
Author: Stuart Turton
advertisement
- Need a bit of extra Christmas cash? Grass up your boss, says BSA
- Photoshop Mobile on Android review: first look
- ATI Radeon HD 5970: 42% more expensive in the UK
- Office 2010 Beta – 32-bit or 64-bit – The Choice is Clear
- Why Britain's watchdogs have fewer teeth than goldfish
- Tabbed documents: how to make Office 2010 great
- Outlook 2010 People Pane – does it spell death to Xobni
- Microsoft Outlook 2010 screenshots
- Co-Authoring in Word 2010 and SharePoint Foundation 2010
- Microsoft Outlook 2010 screenshots: Backstage view
- Getting to grips with Microsoft's IT Health Environment Scanner
- Virtualise your servers
- The changing face of travel gadgets
- Build your own distributed file system
- The bulletproof Dell that costs an arm and a leg
- Microsoft Office 2010 Technical Preview: Q&A
- Lawnmowers, the TyTN II and one odd insurance request
- There'll never be a bulletproof OS
- How far can we trust apps?
- Five nice touches in Outlook 2010
advertisement
Printed from www.pcpro.co.uk


