Sunday, March 22, 2015

Vawtrak Financial Malware


Vawtrak Financial Malware
Vawtrak is a data stealing malware targeting financial transactions globally.
"Vawtrak has followed the success of previous financial bot malware like Zeus and Gameover to become one of the most popular crime kits around. Vawtrak’s owners are operating a highly successful business, running specific campaigns and adding new targets as demand requires.
Vawtrak was the second most popular malware distributed by web-based exploit kits (i.e., by malicious drive-by downloads) during September to November 2014, according to SophosLabs telemetry. It represented 11% of all malware SophosLabs saw distributed in this way during that time period."
http://blogs.sophos.com/2014/12/18/sophoslabs-research-spotlights-rising-threat-of-vawtrak-financial-malware/

Crimeware As a Service for custom targeting

Crimeware As a Service (CWaaS) is helping fraudsters employing botnets  to custom-target enterprises for malware infections and advanced persistent threats

They were used recently for targeting financial institutions:
"In the U.S., for example, the botnet targeted not only large banks such as Bank of America and Citigroup, but also smaller financial institutions not usually hit by cybercriminals -- such as Bank of Oklahoma, Cincinnati's Fifth Third Bank, the Columbus-based Huntington National Bank, and San Francisco's Bank of the West."
http://www.csoonline.com/article/2863193/malware-cybercrime/crimeware-as-a-service-offers-custom-targeting.html


Phishing Mails Strike PayPal Customers

PayPal customers are again and again targeted by Phishing emails.

The mail reads:
""Subject: Your account has limitation! You can resolve this now," the fake electronic mail directs its recipient to validate his e-mail id to update to PayPal's system. It then states that once the validation is done, the recipient can use the id for getting payments from relatives and pals. Over and above, the recipient can make the id his key id for any business he may conduct with PayPal. A link 'Confirm My E-mail Address' is included with which the e-mail ends. - See more at: http://www.spamfighter.com/News-19523-Phishing-E-mails-Yet-Again-Strike-PayPal-Customers.htm#sthash.WNcKeqMI.dpuf "


http://www.spamfighter.com/News-19523-Phishing-E-mails-Yet-Again-Strike-PayPal-Customers.htm