Hackers steal £650 million in world's biggest bank raid

Hackers steal £650 million in world's biggest bank raid

Herbalist Dr MziziMkavu

Platinum Member
Joined
Feb 3, 2009
Posts
43,073
Reaction score
34,844
Investigators uncover what is thought to be the biggest ever cybercrime with more than £650 million going missing from banks around the world


Hackers0_2568369b.jpg


British banks are thought to have lost tens of millions of pounds after a gang of Russian based hackers spent the last two years orchestrating the largest cybercrime ever uncovered.

As much as £650 million is thought to have gone missing after the gang used computer viruses to infect networks in more than 100 financial institutions worldwide.

The hackers managed to infiltrate the bank's internal computer systems using malware, which lurked in the networks for months, gathering information and feeding it back to the gang.

The illegal software was so sophisticated that it allowed the criminals to view video feeds from within supposedly secure offices as they gathered the data they needed to steal.

Once they were ready to strike, they were able to impersonate bank staff online in order to transfer millions of pounds into dummy accounts.They were even able to instruct cash machines to dispense money at random times of the day even without a bank card.

While the criminals behind the audacious electronic raid are thought to be based in Russia, the scale of their crime was truly global with banks in Japan, China, the United States and throughout Europe having been hit.

The scale of the losses by UK based financial institutions has not yet been disclosed, but is thought to run into tens of millions of pounds.

The scam was uncovered by the Russian cybersecurity firm, Kaspersky Lab, which was called in to investigate after a cash machine in Ukraine was found to have been spitting out money at random times.

As investigators began to look into the problem they were staggered by the scale of the crime they uncovered.
A spokesman for Kaspersky Lab said: "The plot marks the beginning of a new stage in the evolution of cybercriminal activity, where malicious users steal money directly from banks, and avoid targeting end users."

Despite the fact the plot has been uncovered, it is feared that banks may still find themselves falling victim as once installed the malware can operate almost independently and is extremely difficult to identify.

The cybercriminals would gain entry to an employee's system through a process called spear phishing, where they would send an email which appeared to come from a trusted source.
Once the email was opened, the malware would infect their system allowing the hacker to jump into the bank's network.

They would then gain access to an administrator's computer providing video surveillance of everything on in the office.

They were able to monitor the screens of staff that serviced the cash transfer systems and after watching how they operated were able to mimic the process needed to move money around.
It is thought the largest sums stolen were taken in bold electronic raids, where hackers would break into computer system and transfer tens of millions of pounds in one go.

On average, each bank robbery took between two and four months, from infecting the first computer at the bank's corporate network to making off with the stolen money.
Another method used was where the criminals would gain access to someone's account and inflate the balance many times over.

They would then withdraw the amount they had increased it by and the person would never suspect because their original balance remained the same.
Sergey Golovanov of Kaspersky Lab said: "These bank heists were surprising because it made no difference to the criminals what software the banks were using.

"So even if its software is unique, a bank cannot get complacent. The attackers didn't even need to hack into the banks' services. Once they got into the network, they learned how to hide their malicious plot behind legitimate actions. It was a very slick and professional cyber-robbery."

Source: Telegraph



 
aisee hiyo hatari hii technology itamaliza watu,,,, benki kubwa hizo zinakuwa hacked ingekuwa NMB je!!
 
Kuna kidudu kinaitwa CryptoWall 3.0 kinafanya encryption ya ajabu kwenye data. Halafu jamaa wa hiki kidudu wanataka malipo ili wakupe private key kwa ajili ya decryption.
 
Sio mchezo,hao ukikamata hamna peleka jela bali unawapa mtaji wafungue cyber security firm itakayo saidia dunia nzima.
 
Sio mchezo,hao ukikamata hamna peleka jela bali unawapa mtaji wafungue cyber security firm itakayo saidia dunia nzima.

Kuna uwezekano pia kwamba ile thrill wanayopata kwa kuinfiltrate systems inawasatisfy personally.

Huwezi kuicompare na the boring non-thrilling job ya kuprotect a system. Hivyo hawatakua satisfied na hako ka mchezo wataendelea nako tu.
 
Kuna kidudu kinaitwa CryptoWall 3.0 kinafanya encryption ya ajabu kwenye data. Halafu jamaa wa hiki kidudu wanataka malipo ili wakupe private key kwa ajili ya decryption.
Crowti update - CryptoWall 3.0

After almost two months of hiatus over the holidays, a new campaign of Crowti tagged as 'CryptoWall 3.0' has been observed. It uses a similar distribution channel as before, having been downloaded by other malware and serving as a payload through exploits.
The graph below shows the spike after two days of no activity from 288 unique machines affected by this malware:


Figure 1. Sudden spike from CryptoWall 3.0 activity this month.
It still follows the same behavior as previous variants, with minimal modifications such as changes in ransom notification file names:

  • HELP_DECRYPT.HTML
  • HELP_DECRYPT.PNG
  • HELP_DECRYPT.TXT
  • HELP_DECRYPT.URL
The files are still customized for each infected user with a personal link to decryption instructions page that are still done over Tor network. Tor (anonymity network) is a free software which enables online anonymity for users who attempt to resist censorship.

Figure 2. HELP_DECRYPT.PNG displays after the files have been encrypted in the system indication information about the malware attack.

Figure 3. HELP_DECRYPT.TXT details the instructions to go to the decryption page that is customized for each infected user.

Figure 4. HELP_DECRYPT.HTML details the instructions to go to the decryption page that is customized for each infected user.

Figure 5. Decryption service or payment page that requests 500 USD/EURO for the first 167 hours or the ransom demand, which increases over time.
As far as coverage goes, Microsoft detects this threat and encourages everyone to always have Microsoft security software up to date, and enable Microsoft Active Protection Service Community (MAPS).
Customers using MAPS can take advantage of Microsoft's cloud protection and are protected with the latest threat variants. MAPS is enabled by default for Microsoft Security Essentials and Windows Defender for Windows 8.1.
You can check if MAPS feature is enabled in your Microsoft security product by selecting the Settings tab and then MAPS. This is also referenced in our previous blog on Crowti, 'The dangers of opening suspicious emails: Crowti ransomware', which discusses other steps that users can take to protect their PC.


Marianne Mallen

Source.
http://blogs.technet.com/b/mmpc/archive/2015/01/13/crowti-update-cryptowall-3-0.aspx
 
Back
Top Bottom