Malware Pursuing Banking Customers

Online banking has proved to be a great advantage and timesaver. No longer does a customer have to wait in long lines at the bank or perform their banking between certain hours before the bank closes. It is so convenient to be able to open the browser of your choice, pull up your banking website, and conduct business with a few keystrokes. Within the United Kingdom security professionals have discovered new malware that pursues bank customers.
Trusteer, a security company, discovered the malware that creeps in past installed antivirus software and steals users log on information with the intent to commit fraud. Silon.var2 has been discovered to have installed itself on one in approximately every five hundred personal computer systems in the United Kingdom and that figure is compared to one in every twenty thousand within the United States. The malware Agent.DBJP was discovered to install itself on one in every five thousand personal computers in the United Kingdom and one in every sixty thousand computers in the United States. Trusteer gave a statement, “To assist in avoiding detection and bringing the greatest amount of return, the smart criminals are utilizing United Kingdom spam and compromised sites based in the United Kingdom to inject malware that seeks our bank customers.”
Trusteer currently predicts there'll be many more losses in the year 2011 due to regional malware attacks and exploitation. “Thisshows a change in financial criminal activity and needs some special focus from financial organizations. Not related to malware such as Zeus, Torpig, and Ambler which seeks banks and enterprises around the globe, financial malware including Silon.var2 and Agent.DBJP are highly sought after. In the United Kingdom, each attack would focus on three to seven or more banks and use them for six to nine months. It changes its list of potential targets, with a different version of the malicious software.”
Other countries affected with this malware include South Africa and Germany. Trusteer stated the premier method to address this problem is for regional banks to come together and share any information possible to identify and handle any future exploitations.
The Zeus Trojan is a new financial problem and malware that particularly exploits the Firefox browser and commits a higher level of fraud against users of online banking. It can even defeat financial banking institutions that use extreme layers of protection. The malware, Zeus 1.4, utilizes HTML injection and tampers with transactions. This means Zeus has the ability to bypass strong transaction signing methods and authentication.
Trusteer discovered the Trojan steals passwords and has probably infected one in every 3000 personal computers, which is a very fast rate of infection for new code that affects financial transactions. “We belive this newer strain of Zeus will greatly increase fraud losses, as close to thirty percent of users perform their banking online with Firefox. The rate of infection is increasing quicker than we have witnessed before. We recommend financial organizations institute a layered scheme to malware blocking with the proper detection, investigation, mitigation and response utilities.” A study conducted by RSA security discovered eighty eight percent of all Fortune 500 organizations in the United States have the potential to have been compromised by some variant of the Zeus Trojan.
CISSP training brings heightened security awareness to any organization, enterprise, IT data center, and consumer. Identity theft, financial transaction death, embezzlement, information intrusion, cyber criminals, and many other insidious entities attack us from every front. It is up to each individual and organization to protect themselves in the best manner possible. The aspects of a good, quality, CISSP training course includes access control, security policies and compliance, network security, security risk management, cryptography, business continuity, disaster recovery, and many more issues. K Alliance training in this area is available for anyone seeking a superior tutorial course and certification training.
About Us: Computer Training Directory is an entire resource of computer based training in a variety of areas. Microsoft certification training lends recognition, higher skill sets, and better career opportunities in your quest for personal and professional career management. The Computer Training Directory hold many training courses in the subjects you use, including Windows training courses, Web development, software management, project management, information security, and more. Computer Training Directory is your location for quality training and tutorials.



