Tuesday, February 17, 2015

"The World's Most Sophisticated Cyber Attack" - How Hackers Infiltrated The Banks & Stole Millions

"The World's Most Sophisticated Cyber Attack" - How Hackers Infiltrated The Banks & Stole Millions

Tyler Durden's picture




 
Since late 2013, The NY Times reports that an unknown group of hackers has reportedly stolen $300 million ­- possibly as much as triple that amount - from banks across the world, with the majority of the victims in Russia. The attacks continue, all using roughly the same modus operandi...

Hackers send email containing a malware program called Carbanak to hundreds of bank employees, hoping to infect a bank’s administrative computer.

Programs installed by the malware record keystrokes and take screen shots of the bank’s computers, so that hackers can learn bank procedures. They also enable hackers to control the banks’ computers remotely.

By mimicking the bank procedures they have learned, hackers direct the banks’ computers to steal money in a variety of ways:

Source: Kasperskly Labs
As The NY Times reports,
In late 2013, an A.T.M. in Kiev started dispensing cash at seemingly random times of day. No one had put in a card or touched a button. Cameras showed that the piles of money had been swept up by customers who appeared lucky to be there at the right moment.

But when a Russian cybersecurity firm, Kaspersky Lab, was called to Ukraine to investigate, it discovered that the errant machine was the least of the bank’s problems.

The bank’s internal computers, used by employees who process daily transfers and conduct bookkeeping, had been penetrated by malware that allowed cybercriminals to record their every move. The malicious software lurked for months, sending back video feeds and images that told a criminal group — including Russians, Chinese and Europeans — how the bank conducted its daily routines, according to the investigators.

Then the group impersonated bank officers, not only turning on various cash machines, but also transferring millions of dollars from banks in Russia, Japan, Switzerland, the United States and the Netherlands into dummy accounts set up in other countries.

In a report to be published on Monday, and provided in advance to The New York Times, Kaspersky Lab says that the scope of this attack on more than 100 banks and other financial institutions in 30 nations could make it one of the largest bank thefts ever — and one conducted without the usual signs of robbery.

...

Kaspersky Lab says it has seen evidence of $300 million in theft through clients, and believes the total could be triple that.
No bank has come forward acknowledging the theft...
The silence around the investigation appears motivated in part by the reluctance of banks to concede that their systems were so easily penetrated, and in part by the fact that the attacks appear to be continuing.

The managing director of the Kaspersky North America office in Boston, Chris Doggett, argued that the “Carbanak cybergang,” named for the malware it deployed, represents an increase in the sophistication of cyberattacks on financial firms.

“This is likely the most sophisticated attack the world has seen to date in terms of the tactics and methods that cybercriminals have used to remain covert,” Mr. Doggett said.

...

Mr. Doggett likened most cyberthefts to “Bonnie and Clyde” operations, in which attackers break in, take whatever they can grab, and run. In this case, Mr. Doggett said, the heist was “much more ‘Ocean’s Eleven.’ ”

“We found that many banks only check the accounts every 10 hours or so,” Mr. Golovanov of Kaspersky Lab said. “So in the interim, you could change the numbers and transfer the money.”

Read More Here...
*  *  *
5
Your rating: None Average: 5 (17 votes)
 


Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.
Sun, 02/15/2015 - 20:24 | 5788516 Victory_Garden
Sun, 02/15/2015 - 20:47 | 5788587 wee-weed up
wee-weed up's picture


How do you think the ChiComs are paying for the massive expansion of their military?
(Which they will eventually use against us)
Sun, 02/15/2015 - 20:47 | 5788594 Master_Blaster
Master_Blaster's picture
Our senior DBA just had a malware attack on Thursday.....think that's bad?
Sun, 02/15/2015 - 21:15 | 5788673 tarabel
tarabel's picture


Only if you're the employee who watches lots of porn on the company system.
Sun, 02/15/2015 - 23:11 | 5788948 NidStyles
NidStyles's picture
Sounds more like someone is either sending a message to the bankers, or they are testing their ability to infiltrate the banking system.

Either way, they would have done us a larger favor had they simply started wiping out debts instead and erasing any trace of them.
Mon, 02/16/2015 - 03:01 | 5789210 Greyhat
Greyhat's picture
Its just the NSA filling some black budget holes! :)
"Western Spy Agencies Secretly Rely on Hackers for Intel and Expertise"
https://firstlook.org/theintercept/2015/02/04/demonize-prosecute-hackers...
Mon, 02/16/2015 - 03:43 | 5789247 commander gruze?
commander gruze?'s picture
Bitcoin users not affected.
Mon, 02/16/2015 - 10:02 | 5789827 funthea
funthea's picture
Thats because the cyber group knows that bitcoin is going much lower, and its future is to be on par with the infinite number of other alt coins. That is the only way bitcoin can survive. Its the only way the masses will start using it. Why spend $234 USD for a bitcoin when you can buy litecoin for $1.80 USD, or any other alt coin for that matter. Wake the fuck up! Stop grasping at straws. Take your loss and move on.
Mon, 02/16/2015 - 10:07 | 5789838 City_Of_Champyinz
City_Of_Champyinz's picture
lol bitcoin.  How much has the value of bitcoin plummeted in the last year again?
Mon, 02/16/2015 - 15:20 | 5791016 commander gruze?
commander gruze?'s picture
If you think it's about the price you're not paying attention.
Sun, 02/15/2015 - 20:49 | 5788595 NoDebt
NoDebt's picture
"Since late 2013"
"with the majority of the victims in Russia"
If that's not NSA or CIA I'll eat my hat.
 
Mon, 02/16/2015 - 07:27 | 5789409 Arnold
Arnold's picture
Just a passing thought, but I wouldn't discount  Russia's new glasnost partner, those sneaky Chinese hoards.
(Or the Norks. Chuckle. Chuckle)
Sun, 02/15/2015 - 20:26 | 5788523 Skateboarder
Skateboarder's picture
Someone, stop those thieves! (no, not the 'hackers' - the guys who counterfieted the 'money' the 'hackers' stole)
Sun, 02/15/2015 - 20:37 | 5788562 A Nanny Moose
A Nanny Moose's picture
The State has more guns, and they are bigger.
Mon, 02/16/2015 - 00:46 | 5789095 ebworthen
ebworthen's picture
Exactly.  These hackers didn't do anything different from what central banks the world over do; they added a zero (or two) to someone's account balance then transfered money to themselves.
The victim account holder might have had $10,000 in their account - the hackers made it $100,000, then transfered $90,000 to themselves in the blink of an eye, account holder still has $10,000.
No diffterent than Ben Bernanke or Janet Yellen hitting Ctrl+P on the FED keyboard and the Treasury giving banks all the "money" they want at 0.5% so they can lend it out at to the sheeple at 4.5%-29%.
Who are the more malicious thieves here, hackers giving themselves some cash or the .gov and bank/corporate interests working together to rob the public treasury while making citizens debt slaves?
Mon, 02/16/2015 - 02:21 | 5789192 NidStyles
NidStyles's picture
Which is all the more reason I am just going to assume that it was the Fed that perpetrated the hack themselves, probably through a proxy to enable it as a justification for an end to the "net-neutrality", or a lockdown kill switch for the whole of the internet.

I expect to see more of these so called "hacks".
Mon, 02/16/2015 - 13:03 | 5790504 Eternal Complainer
Eternal Complainer's picture
Operation: chaos
Mon, 02/16/2015 - 21:16 | 5792477 Arius
Arius's picture
well, one thing is for certain ... these are not small potatoes kind of things run from the garage

 
Sun, 02/15/2015 - 20:27 | 5788530 dufferin
dufferin's picture
'nul ne peut se prévaloir de sa propre turpitude' bank is fraud so...
Sun, 02/15/2015 - 20:27 | 5788531 Osmium
Osmium's picture
Jon Corzine strikes again?
Mon, 02/16/2015 - 00:13 | 5789051 eatthebanksters
eatthebanksters's picture
Only if they are segregated funds protected by law...
Sun, 02/15/2015 - 20:32 | 5788533 knukles
knukles's picture
See, this exactly the front end running that I've talked about with you people brfoer that end runs encryption.
Like the simple commercial software available for parents to keep track of their kid's activities on line which will record every keystroke and scree of every site visited, it's simply downloaded onto the system in question and records the activity. 
Later, the necessary information sought is retrieved and voila, y'all got entry into and command of said system
It end runs (both front and back) encryption.  Just as my acquaintance, the retired crypto analyst at the Uknowhoagency agreed to when offered the paradigm. 
So simple a caveman could do it
This is a no brainer.
If it in any way is connected to the ether-space, it is publicly available.  EOC QED
PS  Also tells you that we as individuals should always hand audit/balance our financial statements with any financial institution by hand.  Just like in the old days.  If ya' don't activity like this takes place, you never ever know it.  That's your second best control over this kind of theft.  The first and best is not to have anything on line .... but your bank is already on line, so no absolute control other than personal eyeball check and balance
Sun, 02/15/2015 - 20:44 | 5788585 nmewn
nmewn's picture
"The first and best is not to have anything on line..."
Ayep.
Sun, 02/15/2015 - 20:47 | 5788593 cornfritter
cornfritter's picture
say what you will sir, but this is going to require billions more dollars, and a good bit more legislation before it is never dealt with
Sun, 02/15/2015 - 21:22 | 5788693 booboo
booboo's picture
Yep, another lettered Big Government agency will need to be created to handle this task. How about the Trade Reliance Intelligence Bureau and Execution or TRIBE for short?
Mon, 02/16/2015 - 09:09 | 5789662 tnquake
tnquake's picture
I suggest the new goverment entitiy be called SHIT for "SHeeple IT"
Mon, 02/16/2015 - 03:41 | 5789246 Exponere Mendaces
Exponere Mendaces's picture
Funny how ex-banker Knukles knows how it all works, encryption and all - but still can't wrap his liver-spotted skull around Bitcoin.
Aww shucks grandpa, you're sooo smart.
LOL.
 
Sun, 02/15/2015 - 20:36 | 5788556 Bossman1967
Bossman1967's picture
The bankers paying themselves out and reporting it as a hack
Sun, 02/15/2015 - 20:39 | 5788566 A Nanny Moose
A Nanny Moose's picture
The first step in robbing a bank is buying it.
Sun, 02/15/2015 - 20:49 | 5788599 Thirtyseven
Thirtyseven's picture
Yep, and probably a tax write off too.
Sun, 02/15/2015 - 20:51 | 5788604 Dragon HAwk
Dragon HAwk's picture
That will come later.. the old I've been robbed  they got 5k, when in fact the robber took 250.00.
 
Sun, 02/15/2015 - 21:04 | 5788643 HonkyShogun
HonkyShogun's picture
If you want to rob a bank, buy a gun.
If you want to rob the world, buy a bank.
Sun, 02/15/2015 - 20:39 | 5788569 DaveA
DaveA's picture
Fortunately, government central banks can print more money to replace what was stolen. OTOH if a Bitcoin bank gets robbed, the depositors are SOL.
Sun, 02/15/2015 - 20:42 | 5788578 nmewn
nmewn's picture
Its not FDIBitC insured? ;-)
Sun, 02/15/2015 - 21:52 | 5788776 Bunga Bunga
Bunga Bunga's picture
The central bank does not replace stolen money. The banks simply rob the customers to get the stolen money back.
Sun, 02/15/2015 - 20:42 | 5788577 A Lunatic
A Lunatic's picture
My guess is this money is quietly being funneled into BlackOps projects. For the children of course........
Sun, 02/15/2015 - 20:44 | 5788583 brown_hornet
brown_hornet's picture
Don't worry. They just have to print to make up for the shortfall.
Sun, 02/15/2015 - 20:52 | 5788584 exartizo
exartizo's picture
are you kidding?
$300 million is NOTHING to the Banksters.
neither is a "paltry" billion here or there.
Now compromised trust in the banking system DOES mean something to them.
And it might possibly explain why so many banksters heads have rolled of late.
Sun, 02/15/2015 - 20:45 | 5788589 Duc888
Duc888's picture



They stole zero's and ones, not wealth.  Any jack ass could just walk over to a terminal and replace the zero's and ones.
Sun, 02/15/2015 - 20:55 | 5788617 Atomizer
Atomizer's picture
How does a hacker steal counterfeit money that has been quantitatively eased by the Federal Reserve under no asset backing? Buying MBS and bonds that hold future maturity to pay back a leveraged obligation. How does a hacker steal money created out of thin air?
Fuck you NSA, suck the smoke up your alert cybercrime ass. If you knew the people, the cable would have never hit the internet news. It would be Classified Intel. Fake stories to catch a phishing story. Stupid cunts trying to validate your budget.
Isn't your mission to predict a crime before it happens? Perhaps cutting your budget will make you more effective or defunct. Boo!

Sun, 02/15/2015 - 21:09 | 5788653 Who was that ma...
Who was that masked man's picture
Note to self:  Sign up for that advanced computer class tomorrow.
Sun, 02/15/2015 - 21:11 | 5788657 Atomizer
Atomizer's picture
01001110 01010011 01000001 00100000 01000011 01100001 01100010 01101100 01100101 00101110 00100000 01010111 01100101 00100000 01101100 01100001 01110101 01101110 01100011 01101000 01100101 01100100 00100000 01100001 00100000 01101100 01100101 01100001 01101011 00100000 01110100 01101111 00100000 01101111 01100011 01100011 01110101 01110010 00100000 01101111 01101110 00100000 01010011 01110101 01101110 01100100 01100001 01111001 00101110 00100000 01010111 01100101 00100000 01100100 01101111 01101110 00100111 01110100 00100000 01110111 01100001 01101110 01110100 00100000 01100101 01100111 01100111 00100000 01101111 01101110 00100000 01100110 01100001 01100011 01100101 00101110 00100000 01001000 01100101 01101100 01110000 00100000 01110101 01110011 00100000 01101111 01110101 01110100 00101110 00100000

Sun, 02/15/2015 - 21:32 | 5788727 billsbest
billsbest's picture
Can't agree with you: 110001100 110001100 110001100 110001100
110001100 110001100 110001100 110001100
See what I mean?
Sun, 02/15/2015 - 21:35 | 5788734 WmMcK
WmMcK's picture
There are 10 kinds of people, those who understand binary and those who don't.
Sun, 02/15/2015 - 21:39 | 5788741 Clowns on Acid
Clowns on Acid's picture
You Sir - are a geek
Sun, 02/15/2015 - 21:51 | 5788773 WmMcK
WmMcK's picture
There's no place like 127.0.0.1
Sun, 02/15/2015 - 22:28 | 5788873 are we there yet
are we there yet's picture
Those are strong cuss words. Tone it down for the children here.
Mon, 02/16/2015 - 03:08 | 5789218 Bearwagon
Bearwagon's picture
01000001 01101100 01101100 00100000 01111001 01101111 01110101 01110010 00100000 01101101 01101111 01101110 01100101 01111001 00100000 01100001 01110010 01100101 00100000 01100010 01100101 01101100 01101111 01101110 01100111 00100000 01110100 01101111 00100000 01110101 01110011 00100001
Sun, 02/15/2015 - 21:12 | 5788661 Al Tinfoil
Al Tinfoil's picture
This bank theft is just the one we are being told about.  How many other instances of bank hacking are being concealed?
But don't worry, the info you have stored in the cloud is completely safe.  
Sun, 02/15/2015 - 21:30 | 5788721 billsbest
billsbest's picture
Where did Ebola go?

As Houston Islamic Center Burns, Firefighter Posts, "Let it burn...block the fire hydrant."


David Harris-Gershon (The Troubadour)RSS
Daily Kos member
Sat Feb 14, 2015 at 08:34 AM PST

As Houston Islamic Center Burns, Firefighter Posts, "Let it burn...block the fire hydrant."


a On Friday morning, part of the Quba Islamic Institute in Houston went up in flames, and local firefighters spent over an hour battling the blaze before extinguishing it, saving the institute's school and mosque. The building set ablaze, which stored religious books, was completely destroyed, and came after the center's staff chased off a masked man from the premises earlier this week.
Houston officials believe the fire was set intentionally, and many are calling for this to be investigated as a hate crime. Unfortunately, the hate which likely ignited this fire wasn't just contained to the blaze, for as news of the fire spread, a retired Houston-area firefighter who still (update: no longer) volunteers for Crystal Beach Fire & Rescue posted the following:
a a
This arson attack happened in the wake of the execution of three Muslim-Americans in Chapel Hill, a likely hate crime which has shaken a Muslim-American community already reeling from an uptick in anti-Muslim hate crimes and speech since the premier of American Sniper. Of course, this uptick must be placed within the backdrop of growing Islamophobia which continues to spread throughout American society since 9/11. Indeed, in the 13 years since 9/11, anti-Muslim hate crimes have been occurring at a steady and alarming rate. Today, Muslim-Americans are five times more likely to be targeted for such a crime than before the "war on terror" and the Islamophobia which now runs rampant in America.
a
Graphic via Washington Post.
The figures shown above are believed to be drastically underrepresented, since reporting is voluntary and the Muslim-American community is deeply wary of law enforcement. Is it any wonder, given that innocent Muslim citizens and communities have been the target of illegal spying and surveillance by U.S. police and are routinely profiled on the streets and in airports? Muslim-Americans in Houston, shaken by this attack, were already shaken not just by the Chapel Hill shooting, but by the bigoted rush of white Americans arguing that the execution of three Muslim-Americans was really just about a parking dispute. They were already shaken because they know to be true what family of the victims understand: that this wasn't about parking, but the same hatred which ignited their place of worship in Houston. They were already shaken by the brutality of the crime in Chapel Hill — leaked information indicates the three young citizens were lined up on the ground, kneeling, and shot in the back of their heads execution style. And they were already shaken knowing that, had a Muslim perpetrated this crime, it would have been proclaimed a terror attack.
Erica Williams Simon addressed this hate in a spot-on commentary on the 'parking dispute' fervor:
I want to someday live in a world where, when a senseless thing like this happens, thinking that bias was the cause seems as absurd as a parking dispute. I want to live in a world where we all feel the safety, community and love that 19-year-old Abu-Salha felt when she told public radio in an interview last summer: “It doesn’t matter where you come from. There’s so many different people from so many different places of different backgrounds and religions. But here we’re all one — one culture.” But until that day, crimes that look, smell and feel like hate will continue to be called hate by those who regularly experience hate. And for those who don’t understand that experience, a simple suggestion:
As investigators work to solve the crime, do something to solve the hate. Actively work to change the unwelcoming, dangerous and prejudiced society that Muslim Americans – and many others – live and die in every single day. That will be an honor to these victims. That will be an honor to us all.
The first thing we must do to 'solve the hate' is to admit, loudly and fervently, that this hate exists. And that this hatred is perpetrated by the the dehumanization of Muslim-Americans in the media, on the screen, and in society at large. Only then will Mosques stop burning.
--§--
What Do You Buy For the Children
David Harris-Gershon is author of the memoir What Do You Buy the Children of the Terrorist Who Tried to Kill Your Wife?, recently published by Oneworld Publications.


Originally posted to David Harris-Gershon (The Troubadour) on Sat Feb 14, 2015 at 08:34 AM PST.

Also republished by Writing by David Harris Gershon, Street Prophets , and Houston Area Kossacks.


EMAIL TO A FRIEND X
Your Email has been sent.

Boehner Says He’ll ‘Certainly’ Allow a Homeland Security Shutdown

Boehner Says He’ll ‘Certainly’ Allow a Homeland Security Shutdown

By
John Boehner. Photo: JIM WATSON/AFP/Getty Images
Just three months after incoming Senate majority leader Mitch McConnell vowed "There will be no government shutdowns," the Republican-controlled Congress is getting awfully close to a partial government shutdown. Funding for the Department of Homeland Security will run out on February 27, and the House has passed a funding bill that guts President Obama's executive action on immigration. That version of the bill can't get through the Senate (not to mention a presidential veto), but House Speaker John Boehner says that's not his problem. "If the Senate doesn’t like it, they'll have to produce something that fits their institution ... The House has acted. We’ve done our job," Boehner said on Fox News Sunday. "Senate Democrats are the ones putting us in this precarious position. And it’s up to Senate Democrats to get their act together."
When pressed on whether he'd actually let DHS funding expire, Boehner said, "Certainly. The House has acted."
Senate Democrats used procedural maneuvers to block the bill three times last week, and they want the House to produce a "clean" funding bill, without the measures to block Obama's immigration action. Republicans don't have the votes to break a Democratic filibuster, and last week moderate Senate Republicans, including McConnell, called on the House to pass new legislation. "We cannot cut funding from the Department of Homeland Security," Senator John McCain said on Meet the Press. "We can work this out … You cannot shut down the government. It’s too serious."
To make matters worse, Congress is in recess this week and will only have four days to resolve the issue at the end of the month. "With every House Democrat now cosponsoring clean legislation to fund DHS, it is clear that the votes are present to pass a bill now if only Speaker Boehner would get out of the way," said Drew Hammill, spokesman for Minority Leader Nancy Pelosi, adding, "Speaker Boehner made it clear that he has no plan to avoid a government shutdown that would threaten the safety of the American people."
A DHS shutdown wouldn't actually affect airport screenings, Coast Guard patrols, or even the processing of applications from immigrants applying for deportation deferments. About 85 percent of Homeland Security employees are considered essential, according to NBC News, so in the event of a shutdown they'll stay on the job, albeit without pay. Still, defending the department would cause disruptions in law enforcement training, the E-Verify system that lets businesses check new hires' immigration status, and grants to first responders around the country — plus, Republicans don't want to send the message that they can't manage to keep the government fully funded, even when they control Congress.

Promoted Stories

Ebola virus death toll in West Africa reaches 9,253 — WHO

Ebola virus death toll in West Africa reaches 9,253 — WHO

February 13, 21:17 UTC+3 GENEVA
These cases were reported from Guinea, Liberia, and Sierra Leone
Material has 1 page
© EPA/AHMED JALLANZO
GENEVA, February 10. /TASS/. The death toll from the current Ebola outbreak has reached 9,253. As many as 22,999 are infected, the World Health Organization (WHO) said in a statement on Friday.
These cases were reported from Guinea, Liberia, and Sierra Leone. In line with statistics, the maximum number of Ebola-related deaths and cases has been registered in Liberia - 3,858 cumulative deaths and 8,931 cumulative cases. Liberia is followed by Sierra Leone (3,363 deaths and 10,987 cases) and Guinea (2,032 deaths and 3,081 cases).
The number of Ebola deaths in these three countries rose by 91 and the number of cases rose by 140 since February 11.
The seven-months downward tendencies in Ebola spread and related deaths gave way to another surge. A total of 124 Ebola-related deaths were reported the week before last, as many as 144 people died of Ebola last week. Before that Ebola-related deaths stood at 99.
Separate cases have also been registered in Mali, Nigeria, Senegal, Spain, Great Britain and the United States. In most of these countries the number of Ebola-related cases does not exceed ten, with the only exception of Nigeria, where 20 people are infected by Ebola virus and eight have died.
The World Health Organization describes Ebola virus disease (formerly known as Ebola haemorrhagic fever) as "a severe, often fatal illness, with a case fatality rate of up to 90%." Symptoms include sudden onset of fever, intense weakness, muscle pain, headache and sore throat. This is followed by vomiting, diarrhoea, rash, impaired kidney and liver function, and in some cases, both internal and external bleeding. The infection is transmitted by direct contact with the blood, body fluids and tissues of infected animals or people. People are infectious as long as their blood and secretions contain the virus. The incubation period is 2 to 21 days. There is no known cure or vaccine for the disease. The only treatment offered is "supportive intensive care.".
Реклама

Contact Form

Name

Email *

Message *