The Underground Ecosystem Of Credit Card Frauds

Slides:



Advertisements
Similar presentations
Chapter 6 E-commerce Payment Systems. Traditional Payment Systems Cash Checking Transfers Credit Card Accounts Stored Value Accounts Accumulating Balance.
Advertisements

Electronic payment Methods: Defined: It is alternative payment mechanism for electronic transactions instead of traditional payment methods like cheque,cash,
Payment Systems for Electronic Commerce
Electronic Payment. Amounts transferred through accounts Money transfer instructions Bank’s computer system Other banks / Businesses.
17-2 Financial Services and Electronic Banking. Types of financial services Savings services Financial institutions accept money for safekeeping. A broad.
Chapter 5 The Banking System
Copyright 2007 Thomson South-Western Chapter 5 Banking Procedures.
Banking: Checking Account What is a Checking Account? An account where money is deposited and kept for day-to-day expenses Also called demand deposit.
Banking:
Economics Paycheck.
© Oklahoma State Department of Education. All rights reserved.1 Credit Cards: More Than Plastic Standard 8. 1 Credit Cards and Online Shopping.
© 2014 CustomerXPs Software Pvt Ltd | | Confidential 1 Tentacles of Fraud #StarfishBanks CustomerXPs Software Private Limited.
The next generation of payments is here. Is your business ready?
Trade Management  Module 4.  Learning Objectives:  Managing receivables  Securing receivables  Sales documentation.
Business Administration term project 2 (25%) financial Management Systems Debit card and credit card payments By Ashleigh Gray.
Banking Savings Checking Credit Cards
Mr. Stasa © You should be able to:  Identify the different parts of a personal check  Complete a personal check  Endorse.
Stop cybercrime, protect privacy, save world. Chris Monteiro Cybercrime, dark web and internet security researcher Systems administrator Pirate / Digital.
Electronic Payment. Amounts transferred through accounts Money transfer instructions Bank’s computer system Other banks / Businesses.
Checking & Savings Accounts Economics What is a Checking Account?  Common financial service used by many consumers (a place to keep money)  Funds.
How to Write Checks and Balance Accounts. Checking Account An account at a bank against which checks can be drawn by the account depositor Check – A document.
PayPal and Other Third Party Payment Options Presented by Meg Monsen, Eric Zeng, and Michael Leonard.
EMV Operation and Attacks Tyler Moore CS7403, University of Tulsa Reading: Anderson Security Engineering, Ch (136—138), (328—343) Papers.
CPUSH 23 February 2015 To Do: -Bring textbook all week! -Research Paper 4 Pages: 3/4 EQ: What is the stock market and how can I invest wisely? Agenda:
Banking in the United States. U.S. Banking System Overview  The Federal Reserve System is the central banking system of the United States.  Regulates.
Digital Payments STEP BY STEP INSTRUCTIONS FOR VARIOUS MODES OF PAYMENT: Cards, USSD, AEPS, UPI, Wallets.
Digital Payments STEP BY STEP INSTRUCTIONS FOR VARIOUS MODES OF PAYMENT: Cards, USSD, AEPS, UPI, Wallets.
Paypal PayPal is an e-commerce business allowing payments and money transfers to be made through the Internet. With a PayPal account, you can send and.
Personal Financial Literacy
Transaction Flow end-end
Tracking Cyber-threat Actors
Checking Account & Debit Card Simulation
Personal Banking and Commercial Banks
Introduction to Depository Institutions
Personal Finance (part II)
E-Commerce Basics You know your excited.
Unit 3 Personal & Business Finance
Credit, Debit, and ATM Cards
BDC Good day everyone, My name is Mark Tanner and I am an Account Manager at the Business Development Bank of Canada, known as BDC. I am delighted to give.
Credit Cards: More Than Plastic
Introduction to Depository Institutions
Introduction to Depository Institutions
Chapter 4 E-commerce Security and Payment.
Checking Account & Debit Card Simulation
Introduction to Depository Institutions
Information on Types of Electronic Banking
Introduction to Saving
Take Charge of Your Finances
Financial Institutions and Services
Depository Institution Essentials
Financial Institutions Electronic Banking Checking Accounts
Accounting, Fifth Edition
Shopping experience! Is it safe to pay online? Ian Ramsey
Credit Cards and Online Shopping
Introduction to Depository Institutions
Third-party Payment options, PayPal Implementation
Banking Chapter 5.
Personal Banking and Commercial Banks
Electronic Commerce Payment Systems
ELECTRONIC PAYMENT SYSTEM.
Banking Chapters 5.
ENDORSING, DEPOSITING & RECONCILING
Chapter 10: Money and Banking Section 3
Introduction to Depository Institutions
Chapter 10: Money and Banking Section 3
Chapter 10: Money and Banking Section 3
Company Name | Phone Number | Website | Address
Checking Accounts Chapter 29 7/1/2019.
A Secret Service Perspective on Credit Card Fraud
Financial Service Providers
Presentation transcript:

The Underground Ecosystem Of Credit Card Frauds Abhinav Singh @abhinavbom #malwaremustdie

Agenda Brief Introduction to Card based Payment Systems. POS Malwares and the Data dumps. Understanding the Underground Shopping Mall. Money flow, Demand & Supply Future Scope, Challenges & Solutions

Processing Card Payments

Key Components

POS RAM Scrapping Malware In a Nutshell ERTFDFDGF!@DF$#%RTF^TRYRTY^&HYT&^FGFDGFY^TGTQAQ#@@%B4096654104697113^SINGH/ABHINAV^ 0806101273590052100000000000000? ;4096654104697113=08061012735900521000000?#112$$&&5yygfrbg*7567 RAM Temporarily Stores the Unencrypted Data MAL.EXE Starts Reading the data in the Primary Memory MAL Meaningful Data is written on Disk Running Processes

Dumped Data %B4096654104697113^SINGH/ABHINAV^ 0806101273590052100000000000000? ;4096654104697113=08061012735900521000000?  

Inside the Plastic Card Image source: Blog.cisco.com

Track 1 & 2 Block Diagram %B4096654104697113^SINGH/ABHINAV^0806101273590052100000000000000?;4096654104697113=08061012735900521000000?

3 Steps to Multi Million Dollar Fraud Attack Sell Shop

The Underground Shopping Mall Malware Authors, Phishing Attackers, Skimmers, Exploiters Etc. Forums and Online Shops Buyers Specialized Services

Malware Authors, Phishing Attackers, Skimmers, Exploiters Financially Motivated. Insider threat, 3rd Party IT Service Provider, Outsider threat Background in Payment Processing and related service development

Forums and Online Shops

Buyers Profile ranges from Newbies to Regular and experienced customers. Can Buy single CC, Dumps of Fullz. Can purchase cards with specific options like Country and City of issue, Card Issuer Bank, Brand(Visa, Master, Amex etc), Genre(Classic, Platinum, Gold etc) Purchase is made using Crypto currencies, wire transfer or money transfer. The price of a single card detail would depend on factors like Brand, Genre, expiry date etc. The cost of dump is calculated based on number of CC details it has. Fullz can be slightly more expensive than others as it contains more detailed information about the card owner.

Online Carding Offline Carding Buyer

Online Carding Process of using the stolen credit card details for purchasing goods online. “Fullz” or details including CVV, Registered Address, Phone etc. is required. Finding a “Cardable” Website.

Cardable Website

Offline/In-store Carding Generating Counterfeit cards. Choose shop/cash-out options. Pick up specialized services based on fraud options.

Generating Counterfeit Cards Magnetic Stripe Reader. Plastic cards/Expired cards/Counterfeit printed cards. Encoder Software.

Generating Counterfeit Cards Software: MSRE, TheJerm, Exeba etc.

Specialized Services in Fraud Ecosystem Runner Dropper Shopper

Runners Individual or group specializing in ATM cash withdrawals. Often generate multiple counterfeit cards for single card to do multiple withdrawals In a go. Have Fake digital wallet, crypto currency, online money transfer accounts to safely withdraw money from stolen cards. Runners are the risk bearers; hence their profit margin is also high. They usually charge the carder between 40 to 60 percent of the money stolen in a single run.

Droppers Serves as the drop point for goods purchased online, thus securing the identity of the actual buyer Works by renting apartments, finding empty houses, registering PO Boxes on fake IDs. Since the Dropper bares a fair amount of risk, his profit percent varies between 30 to 50 percent.

Shoppers Shopper specializes in shopping with the counterfeit cards provide by the carder. The Shopper can be an individual or a group that specializes in conducting nervousness-free shopping of goods using the fake cards. The shoppers also have Fail-safe techniques to doge the payment supervisor in case the card fails to authenticate. Profit cut in the range of 10 to 20 percent. The profit margin for Shoppers depends on the type of good the carder wants them to purchase. Expensive luxury items would require a larger profit share to be paid to the shopper.

Demand & Supply Any new disclosure about POS breach suddenly raises the demand for fresh CC dumps in the market. This leads to a rise in price of new dumps. The problem arises when the demand is less and supply is huge. to keep up the momentum, the shop owners and sellers begin lowering the price of their dumps and cards. This brings down the market valuation thus creating deficit.

Demand & Supply Cost Supply (per 1000 cards) Time (per set of 100 dumps) Supply (per 1000 cards) Time (in months) (per 100 dumps)

Credit Card fraud Ecosystem in a Nutshell

Future Scope, Challenges & Solutions Credit card fraud has been around for years now and with time, the model has grown stronger and better with each passing day. The major challenge that this ecosystem faces is double fraud. The payment industry has been dealing with this issue seriously but the problem lies in the widespread reach of card usage. Enforcing a global policy is not easy. Solutions like EMV or Chip-and-Pin cards and RFID cards exist.

Questions