Showing posts with label crime. Show all posts
Showing posts with label crime. Show all posts

Saturday, 10 September 2011

Ethical hackers battle to prevent 'information security apocalypse'





(CNN) -- Barely a day passes without news of another major computer security breach. Last week a hacking network named "Hollywood Leaks" began their attack on the personal data of celebrities, officially adding the glitterati to a roll of shame that already includes targets as diffuse as Sony, the Church of Scientology and PayPal.

However only a few days before the emergence of this latest hacking outfit, a far less conspicuous but similarly-skilled group met at a London hotel to discuss the other side of all matters of information security, otherwise known as "infosec".

The inaugural 44Con was Britain's first major conference for the good guys of infosec. Among the 300 delegates and speakers were a number of so-called "white hats", programmers and penetration testers specifically employed to discover businesses' weak spots.

Using information from these ethical hackers, manufacturers can remedy or "patch" the problem before its release and companies can take measures to safeguard their data.

Everybody had a look at the Sony thing and thought, 'Oh God, I hope I'm not next.'
Steve Lord, foudner 44Con

Although their more destructive brethren might continue to grab headlines, 44Con demonstrated that the fight against hackers, and other more traditional threats to information security, is also strong.

"The way people use and consume media and share information has drastically changed over the past ten years," said Steve Lord, a security professional and co-founder of 44Con.

"The information that we used to think would stay on a computer, in an increasingly networked world, it goes everywhere. So there is an increasing demand for people to secure that information because otherwise people won't put it there."

44Con attracted representatives from governments and members of the military, alongside risk managers, consultants and students. According to Lord, the roll call included "hackers, freaks, geeks, spooks and kooks," none of whom was required to identify themselves further than a first name.

"It's everyone around the table all looking at the same problems and hopefully coming up with some solutions," Lord said.

High-profile hacking is only one strand of the ongoing battle to protect electronic information from damage or infiltration.

Events at 44Con ran the gamut from workshops demonstrating old-fashioned lock-picking with a paperclip, through discussions of threats to iPads and smart phones and even a presentation of how NASA's transmissions to astronauts have recently been intercepted.

"We've got a serious problem here... like the global financial crisis," said Haroon Meer, a researcher at the infosec consultancy, Thinkst. But although Meer also referred to "our upcoming security apocalypse", others were focused on how intelligence can be used to predict attacks before they occur and, crucially, how to acquire boardroom backing for improved security measures.

We've got a serious problem here... like the global financial crisis.
Haroon Meer, infosec consultant

Infosec professionals often converse in a language that is not always immediately accessible to a layman (executives included), but the result of their endeavors can often be startlingly clear.

"Every single guy at boardroom level that I speak to says, 'Are we going to be the next Sony?'" said Lord, referring to the recent devastating hack on the electronics giant. "Everybody had a look at the Sony thing and thought, 'Oh God, I hope I'm not next.'"

Sony given 'epic fail' award from hackers

Several presentations at 44Con offered chilling demonstrations of the vulnerabilities of common business devices. Alex Plaskett, a consultant at MWR InfoSecurity, who described himself as someone who has been "professionally breaking things" for many years, performed a so-called "drive-by" exploit on a Windows 7 smart phone.

Independent security consultant, Neil Kettle, performed a take-down of the much garlanded online banking security software Trusteer Rapport, running a key-logging program that replicated on screen anything a user might be entering into supposedly secure password fields.

Another security expert Roelof Temmingh showcased the most recent version of Maltego, software that analyzes and compares freely available information from numerous social networking sites.

Using the website of the Executive Office of the President as an example, Temmingh was able to extract specific information such as favored restaurants among White House staffers, as well as other behavioral trends.

"Even if we don't want to attack, what can we learn?" Temmingh asked, before revealing that at least one member of the Bush administration was a fan of Moody's Diner, visited a psychic medium named "Rosemary the Celtic Lady" and was a keen editor of Wikipedia pages.

The examples were deliberately banal and outdated, but the implication was clear. Through similar paths, hackers of more nefarious intentions could determine what versions of browsers are being used in the White House, for instance, and probe specific vulnerabilities. "If you can exploit the browser of a leader, then you've exploited the PC of a president," Temmingh warned.

However it was left to Alexis Conran, a former confidence trickster who appeared in a British TV show called "The Real Hustle", to sum up the challenges still faced by the infosec sector.

"The general public will only take steps to protect themselves if they know what the dangers are," he said.

[CNN]

Cybercrooks prey on 9/11 anniversary

Malware, 'commemorative coin' auctions and fake charity donation



Cybercrooks are gearing up for the 10th anniversary of the 9/11 attacks with a range of malware traps and hacking attempts both on social networks and the wider internet, net security firm BitDefender warns.

The first wave of these attacks comes in the form of the newly established websites offering supposed content such as "Bin Laden alive", "in depth details about the terrorist attack", "police investigation results" and "towers going down" to attract the curious.
The sites are filed with links to scareware and phishing sites. Others have created fraudulent charity donation sites that serve only to line their greedy pockets at the expense of genuine gift-giving sites.

In addition, fraudsters are running fake auctions and sales of items supposedly linked to the devastating attacks such as shards of metal from the twin tower or even "commemorative coins" supposedly minted from silver collected at the attack site.

More scam, perhaps involving malware, can be expected to follow over the coming days.

“Because of the advancement of hacking and spamming technology over the past decade, plus the significance of the anniversary and increased media coverage, Sept 11 this year may prove hectic on the malware front,” said Catalin Cosoi, head of the Online Threats Lab at Bitdefender.

BitDefender says many of the scams likely to be on show are similar to those seen during anniversaries of the London bombings of July 2005.

Cybercrooks marked remembrances of the 7/7 attacks with fake donation requests, spamming of viruses disguised as supposed videos of the assaults and advanced fee fraud email scams. ®

[TheRegister]

People Who Get Malware Also Get Mugged More Than Usual


Our Lifehacker AU comrades point out this interesting fact from Norton's latest Cybercrime report: People who fall victim to malware are statistically more likely to be mugged in real life too. Interesting.
The obvious caveat is that correlation doesn't imply causation, but it is a bit telling to see that these two statistics are linked. Could it be that people who aren't careful online—because honestly, that's what falling victim to malware is—aren't careful in meatspace either?
Norton's internet safety advocate agrees, and says "Clearly these people aren't taking enough care in their real-world interactions and it carries over in their online world." Just think about people you know and how careful they are in their everyday dealings with other people. The more guarded or suspicious you are, the less likely you are to hand over your personal information to a shady site or click a link or open an attachment you're not sure about.
Norton Cybercrime Report (PDF) via [Lifehacker]

Wednesday, 7 September 2011

Cyber crime now bigger than the drugs trade


The global cost of cybercrime is greater than the combined effect on the global economy of trafficking in marijuana, heroin and cocaine, which is estimated at $388bn, a new headline-grabbing study reported.

The Norton Cybercrime Report puts the straight-up financial costs of cyberattacks worldwide at $114bn, with time lost dealing with the crime adding the remaining $274bn, while the global black market in the three drugs costs $288bn.
Every second, 14 adults become the victim of some sort of cybercaper, adding up to over a million victims every day, the report from Norton-maker Symantec said, with young men who access the web on their mobiles the most likely victims.

But despite the large number of victims, people aren't doing enough to stop it for themselves. Although 74 per cent of people say they're aware of cybercrime, 41 per cent of them don't have up-to-date security software and 61 per cent don't use complex, regularly-changing passwords.

“There is a serious disconnect in how people view the threat of cybercrime,” said Adam Palmer, Norton's lead cybersecurity advisor. "Over the past 12 months, three times as many adults surveyed have suffered from online crime versus offline crime, yet less than a third of respondents think they are more likely to become a victim of cybercrime than physical world crime in the next year."

The most common cybercrime issues are malware and viruses, which have affected 54 percent of those surveyed, with online scams second (11 per cent), and phishing catching 10 per cent of adults out.

Cyber-villainy is also on the up on phones, with 10 per cent of adults having been victims of an attack on their mobile, according to the study. The study surveyed almost 20,000 people in 24 countries. ®

[The Register]

Saturday, 3 September 2011

Webcam sextortion perve gets 6 years

Hacked girls' PCs and blackmailed them to pose



A Peeping Tom webcam sextortionist has been jailed for six years after targeting several young women.
Luis Mijangos, 32, a resident of Santa Ana, California, was imprisoned on Thursday after he was convicted of hacking into more than 100 computers, using stolen personal information, to blackmail his young female victims into posing for sexually explicit videos and pictures.
Mijangos, a freelance computer consultant who is confined to a wheelchair, used malware to compromise victims' machines. In one case he posted naked photos of a woman on her friend's MySpace page. In another he posed as a victim's boyfriend in order to trick her into posing for revealing pictures.

Mijangos used modified versions of remote access tools, such as Poison Ivy or SpyNet, which he planted onto file-sharing networks or sent to victims disguised as video clips or songs so that he could gain compromised access to their PCs, Computerworld reports.

The case is the latest in a long list of prosecutions of voyeurs who used computing technology to abuse victims. For example, Adrian Ringland of Ilkeston, Derbyshire, was jailed for 10 years back in 2006 after he was convicted of using spyware to take explicit photos of kids using compromised access to computer webcams. In 2008, a 47-year-old Cypriot got four years for taking illicit snaps of a teenager after he planted Trojan horse spyware to gain remote control of the 17-year-old's webcam. More discussion on the issue and advice on possible countermeasures (use anti-malware and, if in doubt, disable webcams) can be found in a blog post by Sophos here. ®

[The Register]

Tuesday, 12 April 2011

Corrupt bank worker jailed over Trojan-powered tax scam

A former local business manager at a bank who participated in a £3.2m self assessment tax fraud was jailed for three years and three months on Friday.

Nikola Novakovic, 34, conspired with Oleg Rozputnii, 28, to register over 1,050 fictitious taxpayers on the Income Tax Self Assessment system. The pair claimed fraudulent tax refunds under assumed names before laundering the proceeds of the scam via 200 fraudulent bank accounts.

Personal details needed to pull off the racket were extracted from the computers of consumers using an unspecified computer virus. Rozputnii, an illegal immigrant from the Ukraine, used numerous false identities to help commit the fraud, which also involved Dmytro Shepel, 26, a Ukrainian, also from London.

Joe Rawbone, assistant director of HMRC Criminal Investigation, said: "These men ran an audacious scam stealing millions of pounds. They set up hundreds of false bank accounts using viruses to hack into personal computers to gain information. They used their illegal profits to fund lavish lifestyles, buying performance cars including Porches, Mercedes and Jaguars. HMRC takes tax fraud extremely seriously and we will recover any financial gain from this criminal activity."

The scam netted £3.2m between January 2008 and September 2010 when the racket was uncovered following a lengthy investigation by HM Revenue & Customs (HMRC).

Sentencing, Mr Recorder Singh QC said that Novakovic "had abused his position with the bank" as part of a "sophisticated and orchestrated fraud".

Novakovic and Rozputnii pleaded guilty to cheating the public revenue in March. Rozputnii, the main mover behind the scam, was jailed for three years and nine months on Friday. Shepel was sentenced to three-and-a-half years at an earlier hearing in August 2010.

Pictures of the subjects and their cars can be found in a HMRC statement on the case here. ®

[TheRegister]

Wednesday, 23 March 2011

The Seven Deadly Sins of Cybercrime Victims

Like athletes and chess players, cybercriminals are skilled at identifying their targets’ weak points.
Today’s increasingly online and social world offers a host of techniques for preying on potential victims and their weaknesses.
Following are seven weaknesses that you need to watch out for to avoid falling prey to these scams — whether they take the form of emails, social networking chats, or phone calls.
  • Lust: Scammers try to tempt users into action by masquerading as an attractive man or woman, particularly on social networks. You should assume that a flirtatious advance from someone you don’t know has a less-romantic purpose behind it.
  • Greed: Like the adage says, “If something is too good to be true, it probably is.” If you receive a free iPod offer, or a percentage of a Nigerian wire transfer, resist the urge to make a deal.
  • Vanity: Scammers often try to convince potential victims that they have been chosen, that they’re winners, or that they are somehow part of a select group on the receiving end of an exclusive offer. As harsh as it may sound, you should assume you’re not that special.
  • Misplaced Trust: In some scams, cybercriminals attempt to convince you that they represent a high-profile brand and therefore can be trusted. Other times, scammers pretend to be a “friend of a friend” so that your trust for your friend extends to this unknown person. Question any message or phone call that plays on a trust relationship.
  • Sloth: Criminals rely on our laziness to ensure that poorly written messages and shortened URLs don’t rouse suspicion. For instance, many users will click on a link in an email from their “bank”, instead of calling the bank or visiting the bank’s website to determine if the email is legitimate.
  • Excess Compassion: In 2009, one of the most successful scams on Facebook involved criminals hijacking users’ accounts, then posting status updates claiming that the account holder was stranded somewhere and needed money. Many kindhearted people fell for this ploy. Other similar scams involve requesting donations to nonexistent nonprofits when a major disaster occurs, such as the earthquake in Haiti. Maintain a high level of skepticism toward these types of messages.
  • Urgency: Hand-in-hand with compassionate pleas are scams that insist on a fast response and tell you to “act now” or “time is running out.” Double-check these requests with the sender or a colleague, and don’t feel pressured to respond immediately.
Excerpted and adapted from the Cisco 2010 Annual Security Report


[InfoSecIsland]

Monday, 21 March 2011

UK cyclists hit by fraud after online purchase at website

Updated A suspected security breach at popular UK-based biking site chainreactioncycles.com has been linked by victims to multiple instances of fraud.

Various bike enthusiast forums are alive with complaints (here and here) from customers of the site, several of whom are reporting unauthorised charges on their credit or debit cards. The victims are tied together by having shopped at the bike site over the last fortnight or so.

The majority of fraudulent transactions reported seem to involve mobile phone top-ups to either Vodafone or O2, typically two transactions valued at £15 or so for a total fraudulent amount of £30. However, a small percentage of victims have been taken for thousands of pounds.

The experiences of a Reg reader, who wishes to remain anonymous and was the first to tell us of potential problems, seems typical: "I recently purchased items from the online cycling retailer Chain Reaction. A few days after payment went through, I had a couple of fraudulent transactions on my Visa card, which I cancelled, and got money refunded."

Banking regulations in the UK mean that victims should be able to recover the lost sums, but in the meantime they face an anxious wait and the possibility of being short of cash to pay bills until the mess is sorted out.

Chain Reaction Cycles (CRC) released a holding statement, republished via a thread on popular mountain biking portal MoreDirt.com, that acknowledged reports of problems and stating that it had started an investigation. "Our own infrastructure is routinely and independently tested and we are confident that it is robust," it said. "We are working with industry experts including the card processing companies to identify possible causes both inside and outside the control of CRC."

A spokesman for CRC told El Reg that the ongoing investigation, started on Monday, had thus far not come across anything amiss.

Digital forensics blog ForHacSec adds that the common theme of the fraudulent transactions was that they occurred between seven and 10 days after victims purchased goods from chainreactioncycles.com. Purchases at CRC between March 4 to 12 seem to be those most closely associated with subsequent fraud, it adds. ®

[The Register]

Monday, 14 March 2011

UK Government counts the Cost of Cybercrime

The British government has released a report on the annual cost of cybercrime to the United Kingdom. The study mechanism seems greatly flawed, in that it relies almost exclusively on published reports and expert opinions, rather than on any structured gathering of information from victims.

The news was announced in the press this week, for example in the Independent.

They came up with a 2010 annual cost of cyber crime of £27 billion (or $ 43 billion US Dollars). If the costs were projected evenly from the $ 2.2 trillion UK economy to the $ 14.1 trillion US economy, that would estimate our own costs of cybercrime at $ 275 billion (roughly 6.4 times larger economy.) There is no basis to believe that projection is accurate, but the scale is probably similar.

The study was paid for by the OCSIA, the Office of Cyber Security and Information Assurance. It was conducted by Detica, a BAE Systems company.

The full 32 page report is available from the Cabinet Office

They place costs at:
£3.1 billion to citizens with
£1.7 billion in Identity Theft
£1.4 billion to online scams.
£2.2 billion to the government
£21 billion businesses of which:
£9.2 billion in Intellectual Property theft
£7.6 billion in industrial espionage
£2.2 billion in extortion
£1.3 billion from direct theft
£1 billion in costs related to lost customer data

The Intellectual Property theft was certainly not evenly distributed. They put the most likely industries as:
£1.8 billion = pharmaceuticals & biotech
£1.7 billion = electronic & electrical material
£1.6 billion = software & computer services
£1.3 billion = chemicals
£800 million = automobiles & parts
£800 million = non-profits
£400 million = aerospace & defence

The greatest risk in Intellectual Property theft was believed to be untrustworthy insiders who fell to the pressure of bribery.

The Espionage Impact was largely in three areas:
£2.1 billion = financial services
£1.6 billion = mining
£1.3 billion = aerospace and defence
£900 million = software & computer services      

[GaryWarner] via [ComputerSecurityArticles]

Wednesday, 9 March 2011

Barracuda study shows sharp rise in search engine malware, Twitter crime rate

Search engine malware more than doubled in 2010 and the crime rate on Twitter increased 20%, as cybercriminals continue to sharpen their focus and aim attacks at social networking services, according to a new report from Barracuda Networks.


If you're just randomly searching for a trending topic, your chances of getting malware are significantly increased on Twitter.
Daniel Peck,
research scientist
A 2010 study of search engine malware over a 153-day period found that 1 in 5 search topics are connected to malware. The study was highlighted in the Barracuda Labs 2010 Annual Security Report, which found more than 34,000 malware samples over the monitoring period.

Google served up the lion's share of malware-poisoned results (38%), followed by Yahoo (30%), and Microsoft's search engine, Bing, served up 24% of malware during the testing period. Barracuda said its study found malware writers distributing the malicious code more evenly among the search engines. Google began making strides last year, combing through millions of webpages to reduce search engine malware. While Google served up 69% of malware last June, that number decreased 45% by the end of the year.

For example, when LeBron James left Cleveland to play for the Miami Heat in July, trending links on the first page of Google contained rogue antivirus in the first five results, said Daniel Peck, a research scientist who has been studying search engine poisoning and cybercrime on social networks. "If you get there, it's a pretty good chance you're going to be successful," Peck said.

In addition, Barracuda found popular social network site Twitter serving up 8% of malware during the study, evidence that attackers are continually trying to game the system by spreading malware laden links before Twitter's antimalware engines can detect a problem. In a presentation at SecTor security conference in Toronto last year, Fabrice Jaubert of the Google antimalware team said the company continually deploys more technology and people into the process of weeding out malware, but called it a typical cat-and-mouse game, in which savvy cybercriminals find ways to avoid detection.

Barracuda has been analyzing 26 million Twitter accounts for more than two years, and is finding a steady rise in malicious content, Peck said.

Twitter is becoming a victim of its own success, he said. As users are becoming more active, malicious activity also increases, he said. In 2010, the Twitter crime rate (the number of suspended accounts) increased from 1.6% to 2% (20%) from the first half of 2010 to the second half of 2010.

"If you're just randomly searching for a trending topic, your chances of getting malware are significantly increased on Twitter," Peck said, adding that attackers are using many of the same techniques they use on search engine poisoning campaigns.

In addition to shortened URLs, Barracuda cited hijacked accounts as another concern and the ability of attackers to use automated tools to quickly set up fraudulent accounts and spam users of Twitter based on their tweets. Attackers used the NeoSpoloit exploit kit, redirecting users with shortened URLs to poisoned websites. Many of the sites served up rogue antivirus, Barracuda said.

Twitter has been making strides with security, Peck said. The social network had admitted to the Federal Trade Commission that serious security lapses resulted in the hijacking of many high-profile accounts.
The social networking service agreed to periodic third-party reviews of its security program over the next decade. Since then the service has deployed malware analysis engines and is fairly quick to suspend suspicious accounts, Peck said. In September, Twitter began forcing third-party applications using its APIs to use OAuth, a more secure protocol that uses tokens to better protect usernames and passwords, preventing the potential for account hijacking.

"It's kind of like giving someone the ability to enter your house as needed without giving them your full set of keys," said Paul Judge, chief research officer of Campbell, Calif.-based Barracuda Networks Inc.
Judge said the increased security is welcome, but a lot of Twitter accounts are still tied to weak passwords. Some cybercriminals are just guessing the passwords, Judge said. People are also using passwords that they share across different accounts. When the account credentials of as many as 1.3 million users of Gawker websites were stolen by cybercriminals in December, a few days later a large amount of Twitter accounts were hijacked, Judge said.

Judge said password management is getting better, but password managers need better integration with operating systems and browsers to get the human element out of remembering passwords. Peck said two-factor authentication, which is being rolled out with some Google products, could eventually find its way into some social networks.

[Search Security]

Tuesday, 8 March 2011

Nigerian 419 scammer gets 20 years in jail

Nigerian national Peter Maxson Anyanyueze has just been sentenced to 20 years in prison by the National Prosecuting Authority (NPA) at Germinston Regional Court in South Africa.

According to several media reports, Anyanyueze received the following sentence: ten years for fraud, ten years for money laundering, and two additional years, which will run concurrently, for contravention of the Immigration act.

The scam seems fairly typical: Anyanyueze sent out emails requesting help to manage his cash. The scammer claimed he earned 10.5 million bucks from precious metal sales. His millions, he claimed in the email, were being held in a security company in South Africa, and he needed a third-party to move it out and invest it in Europe.

Saudi Arabian Dr Abdulazziz Alheiraqi Nwasser received this scam email and responded, probably thinking this sounded like a solid investment opportunity.

Instead of transferring the money into Nwasser's account, the scammer requested that he make small payments into nominated bank accounts, based in different countries around the globe.

Nwasser did just that, to the tune of almost $300,000!

I don't know about you, but it doesn't seem like a small amount of money. In any case, Anyanyueze never deposited the millions, so our victim Nwasser found himself seriously out of pocket.

So, what can we learn about this?

First, there is nothing really new here. Scams, where someone tries to dupe another, have been around as long as humans have. 419 scams simply take advantage of people though emails that try to pique recipients' greed or pity. The goal is always money, though that is not always immediately obvious.

If you don't know the person who has emailed you, and/or the email is promising riches for some small investment on your part, go on high alert. The simplest approach is to delete it, though you may also want to report it to your ISP so they can look into blocking these emails in future. Do not respond. You will only be confirming the validity of your email address to an unknown and probably dodgy third party.

***

Quite interesting side fact #1
According to Nigerian-law.org, it seems the Advance Fee Fraud act was established in 2006, three years after Anyanyueze was accused of doing this scam. He was however arrested in 2007, a year after the act was put in place. Hmmmm....

Quite interesting side fact #2
According to this report, the National Prosecuting Authority (NPA) spokesperson
"revealed Anyanyueze had fraudulently entered into a marriage of convenience with a female South African to obtain citizenship. 'The state proved in court that the accused and the female person were never in a bona fide spousal or marital relationship, as the female was living with her South African boyfriend with whom she had a child at the time of the said marriage.'"
As a result of this, they tapped on two extra years to his sentence, which he can serve concurrently with the other twenty.

[NakedSecurity]

10 scammers charged with running 419 scam

Ten people were arrested and are now facing charges of wire fraud in US federal court following a successful investigation that has them pegged as perpetrators of an advanced fee scam.



The ten are allegedly all part of the same gang that took advantage of the gullibility of their victims and convinced them to send modest - and not so modest - amounts of money in order to expedite the settlement of a huge inheritance in their name.

Usually dubbed "Nigerian" or "419" scam, it involves scammers posing as government officials or attorneys who are in charge of finding the heirs of wealthy people and settling the disbursement of munificent inheritances. The victims are taken in by their own greed and naiveté.

25-year-old Claudio Uche Dibe, of of Gardena, California, stands accused of being the ringleader of the gang and sending thousands of spam e-mails to potential victims. He is charged with 15 counts of wire fraud, as are 25-year-olds Bright Amesi, of Gardena, and Briceson Loving, of Lawndale. All three of them have been charged and plead not guilty to the charges.

Of the remaining seven, four have plead not guilty, and three are still waiting to be arraigned. All seven are facing charges on 10 counts of wire fraud each.

Among the evidence that supports the charges is and e-mail between the scammers noting that one victim was claiming after the initial small payment that he didn't have any more money, but that the sender believed him capable of sending "big money, which is what we are all after.”

[Net-Security]

Sunday, 6 March 2011

Cyber Crime Costs Over $1 Trillion Globally?

A recent post on LinkedIn's Information Security Community piqued my attention yesterday with the following teaser for a Webinar:
As you may have read recently, Cybercrime is now costing the UK $43.5 billion and around $1 trillion globally.
The UK government report UK Cyber crime costs UKP 27BN/year published on the BBC’s website offers a top-level breakdown of the costs of cybercrime to Britain and is one of the most dubious reports I have seen recently in a long list of security-vendor and political hype around the cyber crime story.

Regardless of how badly UK businesses are hit by cybercrime, there are several extremely weak points in the work done by Detica for the UK government.

a) First  - they don’t have any empirical data on actual cybercrime events.
Given the number of variables and lack of ‘official’ data, our methodology uses a scenario- based approach.
Which is a nice way of saying
The UK government gave us some money to do a study so we put together a fancy model, put our fingers in the air and picked a number.
b) Second – reading through the report, there is a great deal of information relating to fraud of all kinds, including Stuxnet which has nothing to do with the UK cyber crime space.

Stuxnet does not seem to have put much of a dent in the Iranian nuclear weapons program although, it has given the American President even more time to hem and haw about Iranian nuclear threats.

What this tells me is that Stuxnet  has become a wakeup call for politicians to the malware threat that has existed for several years. This may be a good thing.

c) Third – the UK study did not interview a single CEO in any of the sectors they covered. This is shoddy research work, no matter how well packaged. I do not know a single CEO and CFO that cannot quantify their potential damage due to cyber crime – given a practical threat model and coached by an expert not a marketing person.

So – who pays the cost of cyber crime?

The consumer (just ask your friends, you’ll get plenty of empirical data).

Retail companies that have a credit card breach incur costs of management attention, legal and PR which can always to leveraged into marketing activities. This is rarely reported in the balance sheet as extraordinary expenses so one may assume that it is part of the cost of doing business.

Tech companies that have an IP breach is a different story and I’ve spoken about that at length on the blog. I believe that small to mid size companies are the hardest hit contrary to the claims made in the UK government study.

I would not venture a guess on total global cost of cyber crime without empirical data.

What gives me confidence that the 1 Trillion number is questionable is that it just happens to be the same number that President Obama and other leaders have used for the cost of IP theft – one could easily blame an Obama staffer for not doing her homework….

If one takes a parallel look at the world of software piracy and product counterfeiting, one sees a similar phenomenon where political and commercial organizations like the OECD and Microsoft have marketing agendas and axes to grind leading to number inflation.

I have written on the problems associated with guessing and rounding up in the area of counterfeiting here  and software piracy.

Getting back to cyber crime, using counterfeiting as a paradigm, one sees clearly that the consumer bears the brunt of the damage – whether it’s having her identity stolen and having to spend the next 6 months rebuilding her life or whether you crash on a mountain bike with fake parts and get killed.

If consumers bear the brunt of the damage, what is the best way to improve consumer data security and safety?

Certainly – not by hyping the numbers of the damage of cyber crime to big business and government. That doesn’t help the consumer.

Then – considering that rapid rollout of new and even sexier consumer devices like the iPad 2, probably not by security awareness campaigns. When one buys an iPhone or iPad, one assumes that the security is built in.

My most practical and cheapest countermeasure to cyber crime (and I will distinctly separate civilian crime from terror ) would be education starting in first grade. Just like they told you how to cross the street, we should be educating our children on open, critical thinking and not talking to strangers anywhere, not on the street and not on FB.

Regarding cyber terror – I have written at length how the Obama administration is clueless on cyber terror.

One would hope that in defense of liberty – the Americans and their allies will soon implement more offensive and more creative measures against Islamic and Iranian sponsored cyber terror than stock answers like installing host based intrusion detection on DoD PCs

[InfoSecIsland]

Friday, 4 March 2011

The Spam King is free again, claims his spamming days are over

Robert Soloway, one of the most prolific spammers whose activities earned him the nickname Spam King, has been released from prison after a little less than 4 years inside.



He is allowed to go back online, but according to his plea deal, probation officers will monitor his e-mail correspondence and which websites he visits for the next three years.

“If I send out spam e-mails, that’s a violation of my probation. End of story,” he said to Wired. “I’m being very careful. If I send out an e-mail, I’m not even going probably to CC it. I’ll send a unique e-mail to each person.”

After and estimated 10 trillion spam e-mails sent doing his "career", teaching other people to spam, selling spam packages and using botnets to spread the e-mails - and living the good life during all that time - he now lives in a modest studio apartment in Seattle and works in a print shop.

He says he learned the lesson and now wants to help businesses and consumers avoid spam. “I don’t expect anyone to trust anything I say until they see me making good,” he declared. "I would like to assist in some way by basically revealing what went on inside the cybercrime industry."

[Net-Security]

Thursday, 3 March 2011

Five online criminals sentenced in UK

        You might remember our blog post from last August, discussing an online criminal who posted his bail sheet to an online forum.

He has been convicted today in London and received four years in prison. In the same sentencing, two other males and two females were convicted to jail sentences ranging from 18 months to four years and to community service.

Scotland Yard’s release follows:

A group of young internet fraudsters who set up an online ‘criminal
forum’ which traded unlawfully obtained credit card details and tools
to commit computer offences have today been jailed for a
total of 15.5 years.

[A] Gary Paul Kelly (14.04.89 – 21 yrs) unemployed of Clively Avenue,
Clifton, Swinton, Manchester;

[B] Nicholas Webber (10.10.91 – 19 yrs) a student of Cavendish Road,
Southsea;

[C] Ryan Thomas (8.7.92 – 18 yrs) a web designer of Howard Road, Seer
Green, Beaconsfield, Herts;

[D] Shakira Ricardo (14.11.89 – 21 yrs) unemployed of Flat 13, J Shed,
Kings Road, Swansea SA1;

were sentenced today (Wednesday 2 March) for computer misuse and fraud
offences following a two-day Newton Hearing at Southwark Crown Court.
All pleaded guilty at earlier hearings.

+ [E] Samantha Worley (30.09.88 – 22 yrs) unemployed of Flat 13, J
Shed, Kings Road, Swansea SA1 was sentenced on 14 December 2010 to 200
community service for acquiring criminal property.

The gang are believed to have been responsible for the largest
English-language online cyber crime forum and were all arrested on
various dates in 2009 and 2010, following a complex investigation by
officers the Metropolitan Police Service̢۪s Police Central e-Crime Unit
(PCeU).

During an eleven month investigation detectives uncovered evidence that
the defendants were directly involved in the global forum (used by over
8,000 members) which promoted and facilitated the electronic theft of
personal information; credit and debit card fraud; buying and selling
of personal information (including passwords and PIN numbers); the
creation and exchange of malicious computer programs (malware); the
establishment and maintenance of networks of infected personal
computers (BotNets);and tutorials offering advice on how to commit such
offences, including how to evade and frustrate law enforcement activity
and the exchange of details of vulnerable commercial sites and servers.

Founder of the forum was Webber. Having established a web site named
‘www.GhostMarket.net’, he acted as “administrator” and had overall
control of the site (meaning he was able to allow/ban members, remove
or edit their posts, and alter their status on the forum.)

An examination of the rebuilt forum and its database revealed many
thousands of data entries relating to individuals’ personal details
including names, dates of birth, bank details, passwords, paypal
accounts and social security numbers. Site members are believed to have
traded in compromised databases containing thousands of personal
details including bank account numbers, PIN numbers, passwords and
malware including the Zeus Trojan and other types of criminal software,
including credit card verification programs.

The forum included such topics as: ‘Phishing kits (post free phishing
kits and sell them)’; ‘Show off (show us your skills here)’; ‘Tutorials
(post some useful info here)’; and ‘Cardable (post sites you’ve carded
here)’. There was also advice and tutorials on various methods of
evading law enforcement, how to encode blank plastic with credit card
data, and how to hack into sites, and even recipes for controlled drugs
(crystal meth) and a tutorial on bomb making.

Members of the site communicated anonymously by the use of screen
nicknames. They were able to post messages in various forum topics on
the website and send/receive private secure messages to/from other site
members.

During the investigation detectives recovered from the defendants̢۪
computers more than 130,000 compromised credit card numbers, which at
an estimated industry loss of £120 per card, is a potential £15.8
million financial loss in relation to card numbers alone.

On 3 November 2009 detectives arrested Kelly after executing a search
warrant at his home address. A full search of the property was
conducted, with a number of computers and mobile phones removed from
the address for examination.

It was established that Kelly had independently constructed and
distributed across the web a sophisticated Zeus malicious computer
programme which enabled him to infect and compromise over 15,000
computers in over 150 countries, harvesting from them over 4 million
lines of data ­ including huge quantities of credit card numbers and
other confidential, personal information.

Having been provided with relevant passwords by Kelly, detectives were
able to rebuild the GhostMarket forum and its database using files from
his PC.

Prior to this, on 12 October Webber and Thomas were arrested at a five
star central London hotel for using stolen credit card details to pay
for accommodation in the penthouse suite. They claimed to have
responded to an online advert, saying they had paid money to an
anonymous individual.

Bailed to return whilst officers conducted further inquiries, items
including their laptops were seized. In addition they were found to be
in possession of business cards brandishing the ‘GhostMarket’ logo,
advertising it as “A new era in virtual marketing” with the byline
“I’m a carder, ask about me…”

The duo’s involvement in the ‘GhostMarket’ criminal forum was soon
established and inquiries were made to trace them after they fail to
return on bail in relation to the stolen credit card offence.

It was later discovered that on 31 October the pair had flown out to
Palma, Majorca, where they had been living in a rented flat in Port
D’andrax.

On 29 January 2010 they were arrested at Gatwick Airport as they flew
in from Palma.

The following day a search of Webber’s home address revealed a computer
containing a series of files outlining a step-by-step guide to
committing various criminal offences.

Owing to the volume of evidence to be examined and the complexities of
the case, the pair were released on police bail to return at a later
date.

Officers subsequently travelled to Spain and, accompanied by Spanish
Police, attended the flat Thomas and Webber had rented out. The
property was empty, but local enquiries established that the contents
had been posted back to their UK addresses.

Those items, as well as additional computer equipment, were
subsequently recovered.

Through the forensic examination of seized computers and other digital
storage devices, as well as evidence secured through the rebuilt
Ghostmarket site, officers identified Ricardo, a trusted member of the
forum, and she was traced to Swansea, South Wales. Initially joining
the site as a complete novice, over time Ricardo had progressed to
become directly engaged in card fraud and computer malware activity.
Financial enquiries identified a payment made from Ricardo into her
partner Worley’s bank account, incriminating her in the fraud.

Detective Inspector Colin Wetherill, Police Central eCrime Unit said:
“These defendants were accomplished cyber criminals, engaged in the
systematic mass infection of computers in homes and businesses in the
UK and overseas.

“They unlawfully harvested personal and financial information from
their victims to be exploited for financial gain.

“The GhostMarket crime forum was used by thousands of computer
criminals and fraudsters operating worldwide.

“Through it the defendants built an extensive criminal network to
facilitate the wholesale trade of compromised credit card details,
confidential financial and personal information, malicious computer
programmes, and other sophisticated tools and criminal services.

“The arrest, prosecution and conviction of these individuals represents
a significant step forward in our efforts to tackle cyber crime and
reduce the harm it causes.”

+ A full financial investigation into all four defendants is underway.

[ComputerSecurityArticles]

Twitter crime rate rises 20 percent

Barracuda Labs analyzed more than 26 million Twitter accounts in order to measure and analyze account behavior.

The analysis enabled researchers to model normal user behavior and identify features that are strong indicators of illegitimate account use.



Key highlights from the Twitter research include:
  • In general, activity continues to increase on Twitter: more users are coming online; True Twitter Users are tweeting more often, and even casual users are becoming more active. As users become more active, the malicious activity also increases.
  • The number of real Twitter users increased to 43 percent, up from only 29 percent in June 2010.
  • For every 100 Twitter users, 39 have between one and nine followers, while 50 percent of Twitter users have more than 10 followers.
  • Approximately 79 percent of Twitter users tweet less than once per day.
  • After decreasing at the end of 2009, the Twitter crime rate increased 20 percent from the first half of 2010 to the second half of 2010, going from 1.6 percent to 2 percent.
  • Attackers are distributing malware and exploiting vulnerabilities to achieve their malicious goals.
The complete report is available here.

[net-security]

Teen cybercrime forum boss jailed

A UK teenager who ran a prolific cybercrime forum from home has been jailed for five years.

Nick Webber, 19, maintained the Ghostmarket.net market which boasted 8,000 memberships and facilitated a range of crimes including the sale of stolen credit card and personal details.

Police recovered the details of thousands of credit cards from Webber's machines when he was busted in October 2009 after trying to use a counterfeit credit card to pay for a hotel stay. Confronted by mounds of evidence Webber, from Southsea, Hampshire, pleaded guilty to fraud.

Southwark Crown Court heard that members of the gang may have defrauded banks and individuals anywhere between £12m and £20m, depending on whose estimates you believe. In court, Ghostmarket.net was described as a supermarket for cybercrooks, providing guides on how to commit cybercrimes as well as a marketplace for stolen wares.

The personal details of around 65,000 victims were traded through the site.

Even after his release on bail, Webber continued to engage in cybercrime, an aggravating feature that led to a far tougher sentence than might otherwise have been the case.

Three other convicted suspects were convicted in the same case. Gary Kelly, 21, from Manchester, was also jailed for five years after he also pleaded guilty to the same fraud charges as Webber along with conspiracy to make or supply articles for use in fraud and conspiracy to cause unauthorised modification to computers.

Ryan Thomas, 18, from Beaconsfield in Buckinghamshire, who acted as the site admin for Ghostmarket.net, was jailed for four years. Shakira Ricardo, 21, from Swansea, was imprisoned for 18 months after she pleaded guilty to conspiracy to commit fraud and handling criminal property, the BBC reports.

Webber and Thomas jumped bail soon after their initial arrests in December 2009 before they were captured in Majorca and returned to the UK, The Guardian adds. ®

[The Register]

Wednesday, 2 March 2011

iTunes users complain of account hacks

More than six months after reports of wide-scale compromises of  accounts at Apple's popular iTunes online store, there are fresh reports that suggest that the accounts of iTunes users are being used to make fraudulent purchases of music, games and other merchandise. Reports in the Apple forums suggest a pattern of fraudulent purchases of music and iPhone applications stretching back to November. In most cases, with one user reporting $980 in phony iTunes purchases.

Apple did not respond to Threatpost requests for information about the hacks.
The incidents, which have been on the increases since the beginning of February, bear similarities to an earlier rash of hacks that came to light in July, 2010. In that case, attackers used access to compromised iTunes accounts to buy up expensive applications from a number of iPhone application "farms," many based in China. An account of those attacks, reported by TheNextWeb.com, revealed a connection between application farms run associated with a specific developer, Thuat Nguyen, and fraudulent purchases. Many of the apps released by Nguyen became top ranked sellers in categories such as Book Apps on iTunes Appstore due to the fraudulent buys.

In the latest incidents, which affected iTunes users in the U.S., UK and other countries, there is also a rash of fraudulent purchases that share similarities. Visitors to the Apple Support forums report fraudulent in-game purchases of poker chips for a Texas Hold 'em application credited to the game's developer, one "Hongbin Sho." Others report fraudulent application purchases credited to a developer using the handle Lakoo and Gameislive Corporation Limited going back at least to October, 2010.

In all cases, the users report intrusions to their iTunes account that drain the balance of iTunes gift cards or, where accounts have credit cards attached to them, rack up false charges on the card. In other cases, attackers who have compromised the accounts use them as a front to make fraudulent purchases using a third party credit card account, wiping out the user's address and account information and replacing it with another cardholder's information and address, then making the bogus purchases using that.

Its unclear exactly what the connection is between the hacked accounts and the application makers, but the latter group is hardly hiding. The Gameislive.com domain resolves to Lakoo.cn which contains contact information and links to the various games promoted by Gameislive. The domain itself is registered to a "Lakoo" with a business address in Kowloon, Hong Kong.

The security of mobile application marketplaces has become a sore point for platform vendors like Apple and Google. Anxious to build large ecosystems of games to draw users to their handheld devices, the vendors have been accused of looking the other way at shady practices and shoddy work by developers.

At a recent forum hosted by the consulting firm SRA International, experts concluded that there was no easy fix for mobile security, and singled out mobile app stores as an Achilles heel.

Rob Smith, the Chief Technology Officer of Mobile Active Defense told the audience at the Mobile Security Symposium 2011 that mobile marketplaces encourage users to think that the applications they are downloading have been vetted and are reliable, when the opposite is often true. At stake is, potentially, access to corporate assets and data, he warned.

Forum users also took Apple to task for a lackluster response to incidents of fraud. In most cases, the company appears to have refunded monies that were lost through the fraudulent purchases. In other cases, however, Apple merely suggested the users change their password or contact the developer in question.

[ThreatPost]

Bogus support call scams - this time with market research

Bogus support calls continue to plague Australians, with the Queensland Police Service (QPS) recently warning its constituents of a specific "outbreak" of call scams, this time from a call centre claiming to be the Windows Service Centre.

Brian Hay, a Detective Superindent with the QPS (and, not at all incidentally, winner of the 2010 AusCERT Director's Award for Individual Excellence in Information Security), points out that this latest scam seems to be more targeted than previous call-centre scams.
The scammers appear to have done some market research beforehand:
It has become apparent that some of the targeted victims of this scam had previously engaged in a phone survey some weeks earlier. This innocuous survey sought no personal information; however, it did query information regarding the householder’s computer equipment. When armed with this information at a later date, the fraudster is able to gain credibility of consumers to better scam them of their money.
The lessons to learn from this are:

* Don't assume that participating in unsolicited surveys is harmless because you're only giving away modest amounts of information such as the software you use. The scammers don't need to know exactly who you are, or where you live, in order to sound more believable when they contact you in the future. If in doubt, leave it out!

* Don't accept unsolicited calls which try to work on your computer security fears. You have nothing to gain, and everything to lose.

* Don't take a stranger's explanation of errors in Event Viewer or other system logs. If you are genuinely worried, contact a friend. Not a Facebook friend - a real friend. Someone you know, and like, and trust.

* Don't call back or visit websites based on what you're told over the phone or in an email. Find a reliable, physical reminder of where to call or go online - for example, the emergency number on the back of your credit card for banking problems, or the support number on the last bill from your ISP for online concerns.

[NakedSecurity]

Man sentenced to 82 months for malware


A 37 year-old New Hampshire man was sentenced in federal court for his role in an international computer hacking conspiracy and his failure to file income tax returns while living in Massachusetts.

Asu Pala was sentenced to 82 months in federal prison to be followed by two years of supervised release and a $12,500 fine. Judge Gorton also sentenced Pala to forfeit $7,941,336 and to repay the IRS $2,287,993 in back taxes.

In April 2010, Pala pleaded guilty to one count of conspiracy to commit computer fraud and five counts of failure to file a United States income tax return.

Had the case proceeded to trial, evidence would have proved that from 2003 through 2007, Pala and his co- conspirators infected German citizens’ computers with a program that would force the computers’ telephone modems to surreptitiously dial premium telephone numbers rented from German telephone companies by Pala’s co-conspirators.

The premium telephone lines operated like 1-900 numbers such as those used for directory assistance or astrological predictions: the telephone companies charged callers for added expenses on top of standard connection fees and sent a portion of the added expenses to those who rented the premium lines, in this case Pala’s co-conspirators.

The victims were generally unaware that their computers' telephone modems were calling these numbers and charging them these expenses. Victims paid the added charges if they did not notice them on their telephone bills. The telephone companies then sent the added charges to the premium telephone line renters, who divided the proceeds among the co-conspirators, including Pala.

Pala participated in the conspiracy by employing computer programmers to write and edit the computer hacking software and by sending the hacks to co-conspirators.

Although Pala participated in the scheme while based in Massachusetts and elsewhere in New England, he did not target United States’ computers or computer users. Instead, Pala focused solely on computers and computer users in Germany and possibly other European countries, in order, he thought, to avoid prosecution in the United States.