"High Roller" Hacker Attack is Stealing Hundreds of Millions From the Rich
June 26, 2012 3:13 PM
comment(s) - last by
Attack is an extension of the man-in-the-browser attack methodology
Security researchers admit they're still struggling to defeat man-in-the-browser (MitB) attacks. The best-known example of this attack is the Zeus (
, etc.) botnet, which is comprised of machines infected by drive-by-download or phishing attacks.
Researchers are currently only 23 percent effective at detecting and removing Zeus variants, although
attacks on command and control servers
have been somewhat effective. The malware operates via a browser extension in Firefox or via a Browser Helper Object in Microsoft Corp.'s (
) Internet Explorer. The Trojan is used to carry out traditional malware activities, such as spamming and bank transaction interception/modification.
I. Hackers Steal From the Rich, Give to Themselves With Op. High Roller
Now even as researchers continue to struggle with Zeus and
its successor SpyEye
, there's an even more sinister malware storm brewing that Guardian Analytics and Intel Corp. (
) subsidiary McAfee
have been tracking
[PDF], dubbed "Operation High Roller".
The new attack is much more organized, driven via cloud controllers, versus Zeus where infected machines often operated in a rogue lone manner.
Using cloud servers, machines infected with High Roller Trojans are hit with server-based fraudulent bank transactions totaling up to $130,000 USD (€100,000). These very large transactions are ferried through "mule" accounts also operated by the control-servers. The attacks use Zeus or SpyEye for reconnaissance and then use compromised local machines to target large accounts via
"spear phishing" tactics
An example "spear phishing" message from an infected machine. [Image Source: McAfee]
The new multi-approach malware is able to circumvent typical "chip and pin" physical security features, such as the smartcard reader ID systems commonly used in Europe. It targets primarily "high rollers" -- accounts with more than €250,000, the kind commonly maintained by wealthy individuals and corporations. This differs from Zeus and other past attacks that primarily targeted the masses with smaller transactions
Op. high roller is stealing millions from the wealthy [Image Source: The Hibernia Times]
II. Sophisticated Cloud-Commanded Malware Hits U.S.
The attacks initially targeted Europe, but have since spread to the U.S. and Columbia. The hardest hit region in Europe, according to McAfee is the Netherlands, which suffered over €141M ($175M USD). However attacks in the U.S. are also escalating with 8 to 10 malware variants currently attacking 109 businesses.
Texas is the state currently being hardest hit by the attacks. Numerous account holders in New York, Georgia, and California were also targeted.
Many states have been hit by Operation High Roller. [Image Source: McAfee]
Most of the attacks originated from command-and-control servers than Russia, though some C&C servers were also found in China and the U.S., among other places.
This article is over a month old, voting and posting comments is disabled
RE: phishing still works?
6/26/2012 5:00:38 PM
Thanks jerk. I was trying to come up with a way of wording that to convey my thoughts but couldn't come up with the right wording and wasn't going to take forever doing it.
I *acknowledge* that there are stupid people, even after many years of warnings about such things, what surpises me is that it works *so well* Maybe it's just a numbers thing, I'd be interested to know what percentage of people who receive spam like this are actually victimized.
RE: phishing still works?
6/26/2012 5:33:58 PM
Sorry for the 'jerk' comment...I just thought that what I said made sense, and figured more people wouldn't be quite as cynical (which I usually am) about how many people fall for this kind of thing.
"It's okay. The scenarios aren't that clear. But it's good looking. [Steve Jobs] does good design, and [the iPad] is absolutely a good example of that." -- Bill Gates on the Apple iPad
Malware Focusing on Macs, Mobile Devices Increasing
May 24, 2012, 9:18 AM
Wrath of the Titans: Microsoft, U.S. Feds Slay Godly "Zeus" Botnets
March 26, 2012, 3:21 PM
China Appears to Have Committed "Unprecedented" Cyber-Attack on Canada
February 17, 2011, 10:32 AM
Kneber Botnet May Have Infected 75,000 PCs Globally
February 18, 2010, 10:44 AM
Google plans ultra-fast wireless Internet for Research Triangle Park, N.C.
August 12, 2016, 6:30 AM
Twitter Senior VP: "Diversity is Important, But We Can’t Lower the Bar"
November 9, 2015, 9:59 AM
CNN Resorts to Internet Censorship to Promote Clinton Over Senator Sanders
October 15, 2015, 2:47 PM
Breaking Bad: How to Crash Google's Chrome Browser With Just 8 Characters
September 23, 2015, 11:08 AM
Quick Note: Amazon UK Offers £10 Back on Any Order £50 or Over
August 3, 2015, 12:05 PM
Editorial: Reddit Allows Itself to be Hijacked as a Hate Platform For Racist Bigots
July 21, 2015, 6:32 PM
Most Popular Articles
Are you ready for this ? HyperDrive Aircraft
September 24, 2016, 9:29 AM
Leaked – Samsung S8 is a Dream and a Dream 2
September 25, 2016, 8:00 AM
Inspiron Laptops & 2-in-1 PCs
September 25, 2016, 9:00 AM
Snapchat’s New Sunglasses are a Spectacle – No Pun Intended
September 24, 2016, 9:02 AM
Walmart may get "Robot Shopping Carts?"
September 17, 2016, 6:01 AM
Latest Blog Posts
Are farm children less likely to have allergies and asthma in adulthood?
Sep 30, 2016, 5:00 AM
MH 17 shot down by missile 'brought from Russia' into Ukraine's rebel territory
Sep 29, 2016, 5:00 PM
Burlington Gun Attack
Sep 27, 2016, 5:00 AM
Who is in Risk of Getting Oral Cancer?
Sep 23, 2016, 6:02 AM
France Bans Plastic Eating Utensils in Restaurants
Sep 18, 2016, 10:49 AM
More Blog Posts
Copyright 2016 DailyTech LLC. -
Terms, Conditions & Privacy Information