On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet

August 27th, 2009

Hackers mailing malware-infested CDs to banks

Posted by Ryan Naraine @ 10:29 am

Categories: Adobe, Anti Virus, Arbitrary Code Execution, Browsers, Data theft, Exploit code, Firefox, Flash, Malware, Microsoft, Mozilla, Patch Watch, Rootkits, Spam and Phishing, Spyware and Adware, Viruses and Worms

Tags: Bank, Union, CD, Malware, Hacker, Attack, Financial Services, Security, Viruses And Worms, Ryan Naraine

Just call it the throwback attack.  (See important update below)

Reminiscent of the days when viruses were distributed on floppy disks, cybercriminals are currently mailing infected CDs to credit unions and smaller banks as part of a clever offline scheme to load malicious software into computers with valuable data.

According to an alert issued by the National Credit Union Association, a credit union reported receiving a bogus fraud advisory accompanied by two compact discs.

The letter advises credit unions to review training material (contained on the CDs). DOING SO COULD RESULT IN A POSSIBLE SECURITY BREACH TO YOUR COMPUTER SYSTEM, OR HAVE OTHER ADVERSE CONSEQUENCES.

The letter (PDF) contains several spelling and grammatical errors but, as Dennis Fisher points out here, this low-tech attack method can be highly effective because smaller businesses are not properly equipped and educated to deal with these types of threats:

An interesting point here is that the thieves are targeting credit unions, which tend to be smaller, community-based institutions, rather than larger, more sophisticated banks. Many credit unions have just a handful of branches and may not have the dedicated security staffs that national banks have.

In effect, this is simply an offline extension of the highly targeted spear-phishing attacks that have been plaguing smaller financial institutions for a couple of years. But it’s one that’s potentially effective and damaging.

Separately, the Washington Post has a scary report about organized cyber-gangs in Eastern Europe preying on small and mid-size companies in the United States.

Because the targets tend to be smaller, the attacks have attracted little of the notoriety that has followed larger-scale breaches at big retailers and government agencies. But the industry group said some companies have suffered hundreds of thousands of dollars or more in losses.

Many have begun to come forward to tell their tales. In July, a school district near Pittsburgh sued to recover $700,000 taken from it. In May, a Texas company was robbed of $1.2 million. An electronics testing firm in Baton Rouge, La., said it was bilked of nearly $100,000.

In many cases, the advisory warned, the scammers infiltrate companies in a similar fashion: They send a targeted e-mail to the company’s controller or treasurer, a message that contains either a virus-laden attachment or a link that — when opened — surreptitiously installs malicious software designed to steal passwords. Armed with those credentials, the crooks then initiate a series of wire transfers, usually in increments of less than $10,000 to avoid banks’ anti-money-laundering reporting requirements.

I’m willing to bet these malicious Trojans are being installed via known security holes in popular desktop software products.  My advice:  Patch, patch, patch!  Pay special attention to the most commonly exploited software products, especially Adobe Flash, Adobe Reader/Acrobat, popular Web browsers (Internet Explorer, Firefox or Safari), QuickTime, iTunes and RealPlayer.

If you don’t need these software products as part of your business operation, you should immediately uninstall them all.

UPDATE: The SANS ISC is reporting that the mailed CDs were part of a sanctioned penetration test.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 8 Talkback(s)
I understood differently
I thought the article meant these businesses' lost
money via breaches at their banks. Not the the
businesses' themselves were suckered into the
ploy.... (Read the rest)
Posted by: Spats30 Posted on: 09/01/09 You are currently: a Guest | | Terms of Use
Why would a bank/credit union need Flash, iTunes, etc?  kd5auq | 08/27/09
Sounds like an easy way to infect  GuidingLight | 08/27/09
AOL should of thought of this... /eom  Arapey | 08/27/09
LOL  betelgeuse68 | 08/27/09
They did  rparker009 | 08/31/09
These 'Hackers' are infact Pen Testers  iTeaBoy | 08/28/09
schools need this stuff  dgrainge | 08/31/09
I understood differently  Spats30 | 09/01/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Meet Doc

  • Here to help you with your Document Management Needs
  • Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
  • To learn more about this mysterious figure check out his blog on ZDNet and his Workspace on TechRepublic. You’ll be glad you did.
  • Produced by
    ZDNet and