TheNewTopical.com - current events, politics, culture, ethics, economics discussion forum  

Go Back   TheNewTopical.com - current events, politics, culture, ethics, economics discussion forum » Main Forum » General & Current Events

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 22-02-11, 05:19 PM
FredFredson's Avatar
Senior Member
 

Join Date: Dec 2009
Location: North America
Posts: 1,749
Default New type of financial malware hijacks online banking sessions

New type of financial malware hijacks online banking sessions
Posted on 22.02.2011

New type of financial malware hijacks online banking sessions

A new type of financial malware has the ability to hijack customers’ online banking sessions in real time using their session ID tokens.

OddJob, which is the name Trusteer gave to this Trojan, keeps sessions open after customers think they have "logged off", enabling criminals to extract money and commit fraud unnoticed.


This is a completely new piece of malware that pushes the hacking envelope through the evolution of existing attack methodologies. It shows how hacker ingenuity can side-step many commercial IT security applications traditionally used to defend users' digital - and online monetary - assets.

Trusteer have been monitoring OddJob for a few months, but have not been able to report on its activities until now due to ongoing investigations by law enforcement agencies. These have just been completed.

Trusteer's research team has reverse engineered and dissected OddJob's code methodology, right down to the banks it targets and its attack methods. Financial institutions have been warned that OddJob is being used by criminals based in Eastern Europe to attack their customers in several countries including the USA, Poland and Denmark.

The most interesting aspect of this malware is that it appears to be a work in progress, as we have seen differences in hooked functions in recent days and weeks, as well as the way the Command & Control (C&C) protocols operate.

These functions and protocols will continue to evolve in the near future, and that our analysis of the malware's functionality may not be 100 per cent complete as the code writers continue to refine it.

OddJob's most obvious characteristic is that it is designed to intercept user communications through the browser. It uses this ability to steal/inject information and terminate user sessions inside Internet Explorer and Firefox.

OddJob’s configuration data shows that it is capable of performing different actions on targeted Web sites, depending on its configuration. The code is capable of logging GET and POST requests, grabbing full pages, terminating connections and injecting data into Web pages.

All logged requests/grabbed pages are sent to the C&C server in real time, allowing fraudsters to perform session hijacks, also in real time, but hidden from the legitimate user of the online bank account.

By tapping the session ID token - which banks use to identify a user's online banking session - the fraudsters can electronically impersonate the legitimate user and complete a range of banking operations.

The most important difference from conventional hacking is that the fraudsters do not need to log into the online banking computers - they simply ride on the existing and authenticated session, much as a child might slip in unnoticed through a turnstile at a sports event, train station, etc.

Another interesting feature of OddJob, which makes it stand out from the malware crowd, is its ability to bypass the logout request of a user to terminate their online session.

Because the interception and termination is carried out in the background, the legitimate user thinks they have logged out, when in fact the fraudsters remain connected, allowing them to maximise the profit potential of their fraudulent activities.

All matching is case-insensitive, and, using this process of pattern matching, fraudsters using OddJob are able to cherry pick the sessions and targets they swindle to their best advantage.

The final noteworthy aspect of OddJob is that the malware's configuration is not saved to disk - a process that could trigger a security analysis application – instead; a fresh copy of the configuration is fetched from the C&C server each time a new browser session is opened.
__________________
"Patriotism means being loyal to your country all the time and to its government when it deserves it."-- Mark Twain

"Inter arma silent Musae"--when the weapons speak, the muses fall silent.

An't nanum hearm deth, doth hwaet ye willath.

It is forbidden to kill; therefore all murderers are punished
unless they kill in large numbers and to the sound of trumpets. -Voltaire

Economic Left/Right: -3.88
Authoritarian/Libertarian: -4.36
Reply With Quote
Reply


(View-All Members who have read this thread : 4
contracycle, FredFredson, Gilles de Rais, lovewithyou8808
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 06:06 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.3.0