Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security

October 12th, 2012, 10:45 GMT · By

Experts: Banks Should Review Authentication Procedures to Prevent Trojan Attacks

SHARE:

Adjust text size:

Solutionary advises banks to review their authentication procedures for wire transfers
Enlarge picture
According to a report released by the RSA, United States financial institutions should expect to become the targets of cyberattacks. The agency wasn’t referring to the distributed denial-of-service (DDOS) attacks launched by hackers in protest against the Innocence of Muslims video, but the campaign called Project Blitzkrieg.

Project Blitzkrieg is said to rely on a Trojan called Gozi Prinimalka to intercept wire transfers made by the banks’ customers with the purpose of emptying their accounts.

To ensure the operation’s success, the initiators want to target 30 unnamed banks with the help of 100 botmasters that could help in sustaining the attacks.

Researchers from information security firm Solutionary once again highlight that this operation leverages the weak state of security surrounding financial institutions, especially those from the United States.

“Solutionary highly recommends banks review authentication procedures for wire transfers. If not already in compliance with Federal Financial Institution Examination Council (FFIEC) requirements, getting in compliance is a great start,” Robert Jeffries, research analyst at Solutionary’s Security Engineering Research Team (SERT), explained.

The expert warns that one way or the other – directly or indirectly –, this campaign will result in a DDOS attack and not only the targeted companies should be prepared to handle it, but also regular users. That’s because the botnets utilized in massive DDOS attacks are in many cases composed of their work or home computers.

“Sure, this attack could be using computers from a specific source, but without knowing for sure it’s not worth the gamble. As a precaution, ensure your systems are patched and the anti-virus is updated. Also be mindful of your emails,” Jeffries added.

Internauts who want to make sure that their computers are not infected with malware and, implicitly, part of a botnet, should look for suspicious outgoing connections, sudden redirects while surfing the Web, delays in system startup and shutdown, and failures in antivirus updates or scans.

Other signs of an infection include the “mysterious” disappearance of files, unusual system performance and browser crashes.


2,149 hits
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


Regions Bank Website Attacked by Izz ad-Din al-Qassam Hackers

Muslim Hackers Responsible for Attacking US Banks Not Identified or Located

Operation Ababil: Hackers Attack Capital One Website, Reveal Future Targets

Cybercriminal Ring Seeks 100 Botmasters to Launch Trojan Attack on 30 US Banks

Alleged Mastermind of Cybercriminal Project Against US Banks Shows His Face

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM