Underground Marketplace Demonstrates Spyware Impact on Banks
Most people have heard and are aware of the potential impact of key-logging and
spyware/malware software existing on compromised systems.
Many assume this only happens to those individuals at home that do not
have antivirus software and/or are careless regarding the suspect websites they
visit. However, it is a fact that
many unsuspecting corporate networks face similar threats.
It is not uncommon for BAI Security audit engineers to find such major threats
lurking on key systems – even teller stations.
In addition, BAI’s Managed Security Service has identified cases where
unusual outbound traffic patterns proved to be initiated by these internal
threats, which were attempting to distribute sensitive information outside the
organization.
In a recent discovery McAfee security researcher Francois Paget wrote a detailed
accounting of an underground marketplace touting a menu of highly sensitive
personal information for sale. The
information being sold appears to be heisted from legitimate users via spyware.

The full posting and examples can be found by
clicking here.
Francois gave a running commentary of the above diagram in
his blog post:
As you can see in the following screenshot, pricing depends on available
balance, bank organization and country. Additional information such as PIN and
Transfer Passphrase are also given when necessary.
For such prices, the seller offers some
guaranties. For example, the purchase is
covered by replacement, if you are unable - within the 24 hours - to log into
the account using the provided details.
|