Download presentation
Presentation is loading. Please wait.
Published byDebra Prudence Black Modified over 9 years ago
1
The evolution of eCrime and the remote banking channels Presentation to the RHUL MSc Information Security Summer School 9 September 2013 Dom Lucas
2
Overview Setting the Scene Attacks & Exploits Monetising the attack The bigger picture
3
Setting the Scene
4
What is eCrime?
5
Organised Crime Product design & development FinanceResourcingStrategy Intelligence Market Research Customer Base Distribution Governance Risk Analysis Return on Investment Takeovers CompetitionMergers
6
Remote banking?
7
What is being attacked?
8
Why? In economic terms Wider Market Base. Greater ROI. Cost/Benefit Model. In criminal terms I rob banks ‘cos that’s where the money is Willie Sutton c1930
9
Attacks & Exploits
10
Phishing
11
Phishing Explained 1. Attacker creates / hijacks website 2. Phishing email sent 3. Victim directed to phishing site 4. Phished Credentials forwarded to Drop server 5. Creds forwarded to phisher 6. Creds traded on online forums 7. Phishers use credentials to access genuine accounts
12
Phishing evolved MITM/Real-time Phishing Capture & use victim 2-FA pass code in real time thus defeating multi factor authentication. HTML form attachment Doesn't require a phishing a site and so evades traditional phishing takedown. Vhishing & Smishing Use of traditional social engineering techniques to gather credentials Use of VOIP technology to spoof & evade detection
13
Malware
14
ZEUS Spyeye Citadel Carberp ICE IX Shylock
15
Attack vectors www.XXX.com
16
Monetising the attack
17
Beneficiaries/Money Mules Continues to be the Bottleneck lots of credentials not enough mule accounts Money Mule categories The professionals The unsuspecting/duped Developments Pre-Paid card accounts- lack of KYC Fake online businesses International Payments (SEPA) International fraud payments to mule accounts across the EU. Job offer We have found your resume at Monster.com and would like to suggest you a "Transfer manager" vacancy. We have thoroughly studied your resume and are happy to inform you that your skills completely meet our requirements for this position. Our company buy, sell, and exchange digital currencies, like E-gold and E-bullion.
18
Putting it all together
19
Crime as a Service
20
Op HighRoller Customised Zeus / Spyeye variant. Automated. Checked balance. High net-worth accounts >e200,000. Targeted over 60 institutions Global network of mules.
21
The Wider Picture
22
Global View
23
Future Challenges
24
Things to think about
25
The next generation….
26
Don’t underestimate the adversary
27
Maintain situational awareness
28
Questions?
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.