Criminals using real-time hacks to target businesses
Real-time services like Twitter have transformed the web, but criminals are using the same techniques to get past security roadblocks.
A malware researcher has warned about hackers using the real-time web' to target the web pages of businesses like banks and other financial institutions.
Joe Stewart, director of malware research for SecureWorks, spoke to the New York Times about a Trojan called Clampi', which used real-time techniques to attack people who could access corporate bank accounts with particularly big balances.
After the trojan was planted in machines it sent a real-time stream of the user's actions using modified instant messaging software. The hacker could then log in to a user's bank account.
If the bank account was using a one-time temporary password, the hacker could also copy this if it was used. These funds would then be transferred to wherever they needed to go.
Stewart said to the New York Times: "What everybody thought was a very secure identification method, these guys found a low-tech means to get around it."
"They don't break the encryption, they just log in at the same time you do," he added.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
-
What does modern security success look like for financial services?Sponsored As financial institutions grapple with evolving cyber threats, intensifying regulations, and the limitations of ageing IT infrastructure, the need for a resilient and forward-thinking security strategy has never been greater
-
Yes, legal AI. But what can you actually do with it? Let’s take a look…Sponsored Legal AI is a knowledge multiplier that can accelerate research, sharpen insights, and organize information, provided legal teams have confidence in its transparent and auditable application
-
CronRat Magecart malware uses 31st February date to remain undetectedNews The malware allows for server-side payment skimming that bypasses browser security
-
FBI warns scammers are using cryptocurrency ATMs to siphon cashNews Criminals will stay on phone with victims as they make payments, says advisory
-
Mekotio trojan continues to spread despite its operators’ arrestsNews Hackers have used it in 100 more attacks since arrests
-
“Trojan Source” hides flaws in source code from humansNews Organizations urged to take action to combat the new threat that could result in SolarWinds-style attacks
-
What is Emotet?In-depth A deep dive into one of the most infamous and prolific strains of malware
-
Hackers fake DocuSign and offer fraudulent signing methodsNews Criminals impersonate the e-signing company to steal credentials
-
Account takeovers rise nearly threefold during pandemicNews Financial services hit hardest by account hijackers, says Sift report
-
Cyber criminals leak one million credit cards on the dark webNews Among the stolen hoard are customer details from US and Canadian banks