Project Blitzkrieg e-banking heist is a credible threat, McAfee says
McAfee has detected malware activity linked to an online fraud operation allegedly planned by cybercriminals
IDG News Service - Project Blitzkrieg, a coordinated attack against U.S. banking customers allegedly planned for the spring of 2013, is a real and credible threat, security researchers at McAfee have said.
A cybercriminal using the nickname "vorVzakone" announced the plan back in September on a semi-private Russian-language underground forum and invited others to join the project. The goal was to create a network of separate cybercriminal gangs that work together using the same malware and resources for a cut of the profits.
VorVzakone said at the time that the operation will target the customers of 30 U.S. banks using a Trojan program that has been in development since 2008 and has more functionality than Zeus or SpyEye -- crimeware toolkits commonly used to steal money from online banking accounts.
In a report about Project Blitzkrieg released in October, security researchers from RSA said that VorVzakone's Trojan program is based on an older piece of malware called Gozi. RSA dubbed the new variant Gozi Prinimalka.
The ambitious nature of Project Blitzkrieg and the way it was advertised has led to speculation that it's probably part of a law enforcement sting operation. However, after investigating the Gozi Prinimalka malware, security researchers from McAfee believe the project is authentic and the threat is real.
In a new report published Thursday, they reveal there are two main Prinimalka versions: one dubbed "nah" that dates back to 2008, lending credibility to VorVzakone's claim that the Trojan program has been in development since 2008, and one dubbed "gov" that first appeared in April 2012 and was probably used as a pilot for Project Blitzkrieg.
According to McAfee's report, older attack campaigns based on the "nah" version primarily used command and control servers hosted in the Ukraine, while the more recent attack campaigns based on the "gov" version used servers hosted in Romania,
The first "gov" Prinimalka campaign using servers in Romania started in early August 2012 and the latest one started in October. All of them targeted the customers of U.S. banks.
Based on McAfee telemetry data, the latest activity seen from the October Prinimalka campaign was on Nov. 30, Ryan Sherstobitoff, a McAfee Labs researcher, said Thursday. The fact that a campaign started in October suggests that the project is moving forward, he said.
Several hundred computers in the U.S. are currently infected with Gozi Prinimalka, Sherstobitoff said. It's not clear if attackers are already stealing money from victims' bank accounts, but it's certainly possible, he said.
That said, not everyone whose computer gets infected with the malware will automatically become a victim of bank fraud. The attackers will likely identify the most valuable accounts and focus on those, Sherstobitoff said.
- Why Projects Fail CIOs are expected to deliver more projects that transform business, and do so on time, on budget and with limited resources.
- The New Business Case for Video Conferencing: 7 Real-World Benefits Beyond Cost-Savings This whitepaper provides insight into the value of video conferencing in today's business environment, and how organizations are using visual collaboration to find...
- Gartner Magic Quadrant for Client Management Tools The client management tool market is maturing and evolving to adapt to consumerization, desktop virtualization, and an ongoing need to improve efficiency.
- Audit Ready and Asset Optimized: The Solid Promise of an Intelligent Software Asset Management Solution In this paper Frost & Sullivan examines the benefits of enterprise-grade Software Asset Management solutions, and how these solutions serve as the convergence...
- LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy... All Cybercrime and Hacking White Papers | Webcasts