Bruce Schneier | |||||||||||
Schneier on SecurityA blog covering security and security technology. « Friday Squid Blogging: Handmade Giant Squids | Main | U.S./Canadian Dispute over Border Crossing Procedures » May 5, 2007New Trojan Mimics Windows Activation InterfaceWhat they are calling Trojan.Kardphisher doesn't do most of the technical things that Trojan horses usually do; it's a pure social engineering attack, aimed at stealing credit card information. In a sense, it's a standalone phishing program. More info here. Posted on May 5, 2007 at 7:59 AM • 16 Comments To receive these entries once a month by e-mail, sign up for the Crypto-Gram Newsletter. Pond Life • May 5, 2007 10:19 AM Good social engineering but I think the trickster went a bit too far here. The second screen illustration asks for the a credit card and ATM PIN number! I'd like to think that most people would spot something that badly out of place. Area 42 • May 5, 2007 10:46 AM They went to all that trouble but then you see, in bold text, "We will ask for you billing details". Stephen Touset • May 5, 2007 11:11 AM Besides the spelling mistakes, the whole thing reads completely unlike the actual Microsoft activation screens. Not just the text, but the flow and style of the text. Plus, they ask you for your ATM PIN. Who asks for that!? bitprophet • May 5, 2007 12:44 PM @Area42 and Stephen: you may be right about the mistakes, but seriously--phishing attacks are not targeted at us, but your average computer user, who has a far greater chance of not noticing such mistakes, or simply not realizing their implications. Somebody Anon • May 5, 2007 12:55 PM Unfortunately, this attack is targeted at lay users. I doubt they would find it strange to answer these questions. Clever social engineering is all about fooling "some people all of the time". D.J. Capelis • May 6, 2007 5:06 AM > Yeah.. but will it run on Linux? Sure, a similar attack can be launched on linux. I'd do it with @reboot in cron, but linux users tend to be less willing to fork over their personal information to some "validation" script because that type of thing doesn't happen to much on that platform. Though I'm sure it could be effective against some RHEL users. Then again, businesses usually don't fork over credit card numbers as easily as end-users. Still probably would get a few though... and that's all you need really. You'd only have to write a small python script. FP • May 6, 2007 1:25 PM @Baron: This seems like the kind of thing that's easy to trace. Following the money is always a good idea. But crooked merchants directly submitting fake charges to the credit card companies are just one way for the phishers to profit. With the ATM PIN, the phishers can go to any ATM and get a cash advance. Sometimes, if the user submitted a debit card, the PIN is also good for the victim's online banking account. They can also purchase goods from online vendors, have them delivered to a mailbox, and then sell them for cash. Max • May 6, 2007 5:35 PM This couldn't happen without their first being a windoze activation. I blame Microsoft. Ralph • May 6, 2007 6:49 PM Think of your poor old mum. She can't logon to her bank any more because the site isn't really their site (it's being proxied to collect her logon), microsoft are asking for her credit card or her system won't run (but it isn't really them), the internet sometimes runs slowly because a trojan on her PC is busy with it and last night the lawyers from RIAA left a message on her machine telling her she's off to court because her grandson downloaded a song with her PC last month. Thomas • May 6, 2007 9:10 PM @D.J. Capelis I'm a linux user. What's this 'rebooting' and 'activating' you speak of?
Joe Blow • May 6, 2007 11:15 PM The pirates seemingly can make Windows do anything yet I cannot open a simple folder without the system freezing up. Wyle_E • May 7, 2007 6:42 AM While upgrading my Ubuntu system to 7.04, a power glitch struck at just the wrong moment, somehow trashing the MBR. When I rebooted from the CD, I thought of what I'd been hearing about Windows in recent weeks and told the partitioner to take the whole disk. After two years of dual-booting, I've officially defenestrated. Now, if I could just get my wife to run her favorite games (all small ones, like Text Twist) from WINE, I wouldn't have to worry about someone using her machine to empty our checking account. Artis Ivis • May 7, 2007 6:52 AM It seems to me that Microsoft will take worthy measures. The virus will not find of itself application.
Post a comment
Powered by Movable Type. Photo at top by Geoffrey Stone.
Schneier.com is a personal website. Opinions expressed are not necessarily those of BT. |
|
Comments