RSA, The Security Division of EMC, provider of information infrastructure, has announced that its 24x7 Anti-Fraud Command Center (AFCC) has uncovered a new phishing kit being sold and used online by fraudsters.
This new kit, a Universal Man-in-the-Middle Phishing Kit, is designed to facilitate new and sophisticated attacks against global organizations in which the victims communicate with a legitimate web site via a fraudulent URL set by the fraudster. This allows the fraudster to capture victims' personal information in real-time.
RSA's analysts researched and analyzed a demo of the kit that was being offered as a free trial on one of the online fraudster forums that the AFCC monitors regularly.
Using the Universal Man-in-the-Middle Phishing Kit, the fraudster creates a fraudulent URL via a simple and user-friendly online interface. This URL communicates with the legitimate website of the targeted organization in real- time - whether it is the online banking site of a financial institution, the order tunnel of an ecommerce company, or any other such business transacting with its users online. The victim receives a "standard" phishing email, and when clicking on the link s/he is directed to the fraudulent URL. The victim then interacts with genuine content from the legitimate website - which has been "imported" by the attack into the phishing URL - thus allowing the fraudster seamless, invisible and immediate access to the victim's personal information.
It is a "universal" phishing kit, meaning it can easily be configured per target. Fraudsters who want to initiate a phishing attack do not have to purchase or prepare a custom phishing kit for each target. Once they acquire and operate this kit, the attack can be configured to "import" pages from any target website. Unlike standard phishing attacks, which only collect specific requested data (typically login and card-related credentials), this attack is designed to intercept any type of credentials submitted to the site after the victim has logged into his account as well.
"As institutions put additional online security measures in place, inevitably the fraudsters are looking at new ways of duping innocent victims and stealing their information and assets. While these types of attacks are still considered 'next generation,' we expect them to become more widespread over the course of the next 12-18 months," said Marc Gaffan, director of marketing, Consumer Solutions at RSA. "We are working with many organizations to ensure they are positioned to withstand whatever threats fraudsters may create. Some of these organizations have already deployed various layers of protection and others are in the process of strengthening their security."
RSA Discovers Universal Phishing Kit
By: Sharon Khare
| Jan 13, 2007
| Ads by Google | ||
Why don't you post one?
LATEST NEWS
- Opera 9.6 Announced, Goes Desi
- TGS 2008: Halo: Recon Details Emerge
- HTC Touch Diamond Contest is Now Live
- Sony Launches VAIO Z Laptops
- Fallout 3 PC Specs Revealed
- Fujitsu Unveils The LifeBook U2010
- India is Top Spam Sender in Asia
- TGS 2008: Bionic Commando Delayed
- TGS 2008: 7 New Arcade Titles Heading to XBLA
- TGS 2008: Ninety-Nine Nights II Announced
| Ads by Google | ||
RELATED
Hot Searches & Keywords :
AMD
ATI
Acer
Adobe
Apple
Asus
Benq
Blackberry
Blizzard
Blu-Ray
Bluetooth
CES 2007
Canon
Capcom
China
Creative
DVD
Dell
E3 2007
E3 2008
EA
Electronic Arts
Facebook
Google
HP
Halo
IBM
ITunes
Intel
Internet
Ipod
LCD
LG
Linux
Logitech
Microsoft
Mobile
Mobile Phone
Mobile Phones
Motorola
Mp3
Myspace
Nintendo
Nokia
Nvidia
PC
PMP
PS2
PS3
PSP
Philips
Reliance Communications
Samsung
Sandisk
Search Engine
Skype
Smartphone
Sony
Sony Ericsson
Toshiba
Ubisoft
Valve
Vista
Voip
Website
Wii
Windows
Windows Mobile
Windows Vista
Xbox 360
Xbox Live
Xbox360
Yahoo!
Youtube
Zune
digicam
digital camera
iPhone
laptop
mp3 player
printer
social networking site
test
yahoo
| Ads by Google | ||
|
|
Sections
Products
Camcorders |
Controllers |
CPUs |
Desktop PCs |
Digital Cameras |
Digital Video Recorders |
DVD Players |
Games |
Gaming Consoles |
General |
GPS Systems |
Handhelds / PDAs |
Hard Drives |
Headphones & Headsets |
HiFi Audio Systems |
Home Theater Systems |
Input Devices |
Internet |
Laptops |
lenovo |
Low Level Components |
Mac Systems |
Mobile Phone Accessories |
Mobile Phones |
Monitors |
Motherboards |
MP3 / Audio Players |
Multi-Function Devices |
Networking |
Optical Drives |
PC Accessories |
PC Add-on Cards |
PC Cabinets |
PC Games |
Printers |
Projectors |
RAM Modules |
Scanners |
Software |
Speakers |
Telecom |
TVs |
Video Players |
