September 26th, 2008

How Online Fraudsters Are Using SaaS in Their Networks

By Chris Preimesberger

It’s now possible for anybody to purchase online criminal services on a monthly fee basis — if you know where to go. As the bad guys get more sophisticated, false bank Web sites are becoming harder to identify from legitimate ones. Even more caution is now needed to stop these frauds, a noted online security expert says.

SANTA CLARA, Calif. — Apparently, there are some real career paths available in the online fraud business. One can become an identity harvester, a software developer who builds botnets, a delivery middleman, a salesperson — the list is long and resembles legitimate businesses in many ways.

At an analysts’ briefing Sept. 25 at EMC’s Silicon Valley offices, RSA Security head of new technologies Uri Rivner told attendees that the Internet fraud business has grown so large and enmeshed in legitimate online activities that it is becoming increasingly difficult to tell who’s good and who’s bad.

Rivner pointed out two recent trends: a) Fraudsters using SaaS (software as a service) model to sell their services to customers for a monthly fee, and b) the appearance of new super-Trojans that hijack legitimate bank Web sites and fool people into entering personal financial information — such as ATM account numbers and personal identification numbers — into the phony Web site.

In describing the hosted fraud model, Rivner said that if a willing participant knows where to go, he or she can simply order a phishing or other criminal business service online and pay a fee per month to participate as an investor in order to share in the “profits.”

“This fee at one of these services is $299 per month,” Rivner said. “This puts you into the food chain of [identity] harvesters, phony ATM card makers, delivery specialists — a whole infrastructure of criminals.

“There looks to be quite a career path in there for some people. Everybody’s a specialist in this realm, and reputation is paramount.”

Of course, trusting any of these anonymous folks online is another issue that an “investor” or “customer” has to solve.

The second trend, involving the new Trojans — which can get installed on an unsuspecting computer owner’s machine through either opening a executable file or by a browse-by Web site, which is fairly rare — is also a growing problem, Rivner said.

“In this scenario, with the Trojan on the client and working, the user goes to his or her bank’s Web site to make a transaction. The Trojan is alerted to this when the site is brought up. When it does show up, it waits for the user to log on, then brings up the false site, which looks very similar to the legitimate one,” Rivner said.

“Except there’s one difference: The false site has two more lines of information it asks for: an ATM account number and the user’s PIN. Once the fraudster gets that info, the account is soon drained,” Rivner said.

Rivner advised online bank users never to take the sites they use for granted.

“Keep a close eye out for changes in the site. Make sure that your connection is a secure one,” he said. “If anything looks a bit different than usual, that should be a red flag. It’s probably a ruse.”

Most banks do not ask for account numbers and PINs, he said. That would be the first clue that something’s amiss.

Most of these online crooks use IRC (Internet relay chat) to communicate — most often in code — and, naturally, aliases. They build their reputations within the network by getting credit for helping facilitate large fraud deals involving banks, savings and loans, hedge funds and other financial institutions.

More news in the online security sector surfaced Sept. 25, when reports revealed that Neosploit, a black-market hacker exploit kit that many security experts believed had been shut downmonths ago, has reappeared on the scene and is responsible for an increase in attacks.

Ian Amit, director of security research at Aladdin Knowledge Systems Inc. said that rumors of the kit’s “retirement” last summer were off base.

RSA, one of the most well-established software security companies in the world, has shut down about 100,000 online fraud schemes in the last several years, Rivner said.

“But there are still plenty more to get, and there are new ones popping up every day,” he said.

8 Responses to “How Online Fraudsters Are Using SaaS in Their Networks”

Bank Needed Bad Credit Payday Loans says:
October 18th, 2008 at 4:46 am

I found you on yahoo while searching for bank needed bad credit payday loans. I just Stumble it on Friday!

Florida Loans Home Purchase Home Loan Secure Online says:
October 27th, 2008 at 8:50 am

Very interesting post. A little bit confusing, but it still ok Hm?.

Florida Loans Home Purchase Home Loan Secure Online says:
October 30th, 2008 at 6:58 pm

I can not agree with you in 100% regarding some thoughts, but you got good point of view?…Definition Of Home Equity Loan Second Mortgage

Online Home Equity Loan Specialists says:
November 4th, 2008 at 5:34 am

I don?t mean to be too in your face, but I?m not sure I agree with this. Anyhow, thanks for sharing and I think I?ll come to this blog more often?.

Online Credit Card Savings Account Payday Loan says:
November 8th, 2008 at 7:23 am

You really poses much expertise on ine Fraudsters Are Using SaaS in Their Networks | SuaraNews.com. I really enjoyed going through your posting. I really appreciate it.

Payday Loans Using A Savings Account says:
November 13th, 2008 at 1:40 am

I happened upon this site while following the links from another site. Your site is wonderful and i bookmarked it. Thank your for the hard work you must have put in to create this wonderful facility. Keep up the excellent work

Account Bad Credit Loan Payday Savings says:
November 13th, 2008 at 6:27 am

Hi there I was browsing Internet searching for account bad credit loan payday savings and your blog regarding ine Fraudsters Are Using SaaS in Their Networks | SuaraNews.com came my way. Very interesting! You really do know your thing! I?m gonna bookmark you and come back in a few to see your new posting! Looking forward to! Cheers!

Jim Spence says:
November 13th, 2008 at 7:39 pm

I was searching for Blogs about customer free loan new payday and found this site. I am interested in your content and appreciate sites like this.

Leave a Reply