Showing posts with label visacard. Show all posts
Showing posts with label visacard. Show all posts

10/17/12

Fake PayPal and WebEx Notifications Lead to Malicious Flash Player Update






security experts are seeing more and more fake emails designed to lead users to malicious Adobe Flash Player update websites. The latest ones spotted leverage the names and reputations of PayPal and WebEx.
Researchers from GFI Labs have found phony notifications that claimed to be from SkypeADP andFacebook. Trend Micro, on the other hand, has identified messages allegedly originating from PayPal’s Bill Me Later service and WebEx to be involved in the same campaign.

“We had an issue this morning with our WebEx and therefore, please accept the new invitation. This invitation has the Conference ID #36189133. Sorry for any confusion,” read the emails entitled “Important – Please read regarding this afternoon’s Webex.”

The alerts that appear to be sent by Bill Me Later bear the subject “Thank you for scheduling a payment to Bill Me Later” and they inform recipients of a payment that’s been made of over $1,000 (800 EUR).

When users click on the links contained in these emails, they’re taken to a website that almost perfectly replicates the Adobe Flash Player download website. Experts highlight the fact that the attackers have gone to great lengths to make sure that the drop menu on the fake webpage imitates the one of the genuine site.

The so-called Flash Player update is actually a malicious element identified by Trend Micro as TSPY_FAREIT.SMC. When it’s executed, it drops a version of the ZeuS banking Trojan onto the infected computer.

“These variants are specifically crafted to steal online banking credentials such as usernames, passwords, and other important account details. These stolen information are then used to initiate transactions without users knowledge or are peddled in the underground market for the right price,” Trend Micro Threat Analyst Jocelyn Racoma explained.

Researchers underscore the fact that it’s probably not a coincidence that the name of WebEx – a popular technology for business conferences – is leveraged by cybercriminals. It’s believed that these particular attacks are aimed at businesses and their employees.

Major Chinese Cybercriminal Gang Dismantled by Authorities, 58 Arrested





Chinese authorities have arrested a total of 58 individuals believed to be connected to what’s called the largest cybercriminal scheme that China has seen so far. The fraudsters are suspected of stealing around 300 million Yuan ($47,953,200 or 36,600,000 EUR) from their victims.
The cybercrooks used a piece of malware in order to steal online payment details. Then, they would use the stolen credentials to purchase online game credits which they sold to players.

Their targets – many of them shop owners – would be contacted via QQ messenger and presented with a hard-to-refuse offer. By tricking the users into clicking on malicious links, they could push the information-stealing virus onto their computers, Sina informs.

The Trojan they used to steal their victim’s online banking details was cleverly designed to avoid being detected by antivirus solutions. 

As a result of the police investigation, 112 computers and 456 payment cards have been seized.

8/11/12

NEW 'GAUSS' VIRUS TARGETS FINANCIAL TRANSACTIONS





(Agence France-Presse) A new “state-sponsored” cyber surveillance virus dubbed “Gauss” has stolen passwords and key data from thousands of bank users in the Middle East, the top IT security firm Kaspersky Lab said Thursday.
According to Kaspersky, Gauss was a complete and “complex, nation-state sponsored cyber-espionage toolkit,” which aims to steal sensitive data, with a specific focus on browser passwords and online banking account details.
It has similarities to Stuxnet and Flame, the Russian company said in a statement, noting that although the new malware program was discovered in June 2012 it appears to have been in use since September 2011.

8/3/12

Google Wallet now accepts multiple cards



NEW YORK (CNNMoney) -- Google just took your phone a step closer to replacing your wallet in the mobile payment revolution.


The company expanded its mobile payments platform, Google Wallet, to accept multiple credit cards. Users can now connect their Visa (V,Fortune 500), MasterCard (MA, Fortune 500), American Express (AXP, Fortune 500), or Discover (DFS, Fortune 500) cards with the new version of Google Wallet. It's an update from the company's previous partnership with MasterCard, Citigroup and Sprint.

Instead of swiping a card, users enter their card info into the service and are able to tap their phones at venues accepting Google Wallet payments. It's a step forward for the company looking to delve into the mobile payment realm - an increasingly crowded space.
The latest update also provides a cloud-based version of the app -- a move Google (GOOG, Fortune 500) hopes will provide more security for users. The feature allows users to remotely disable Google Wallet if a phone is lost or stolen.

Google Wallet only works on near-field communication (NFC) -enabled devices, and is limited to Sprint (S, Fortune 500), Virgin Mobile devices and the Nexus 7 tablet.
There are now twenty-five national retailers -- from Macy's (M, Fortune 500) to Duane Reade -- accepting Google's mobile payment app and according to Google's post about the update, 200,000 locations where people can use Google Wallet.
While it's a step forward, Google admits it still has a long way to go. Most people haven't ditched their wallets for smartphones and several phones on the market don't have NFC capability, which is integral for Google Wallet.
"Changing behavior is very difficult," Robin Dua, who heads product management for Google Wallet, told CNNMoney. "This evolution will require retailers and issuers to make changes, and it's going to take some time."
But Dua says the process has started. The product manager pointed out that smartphones manufactured with NFC chips are becoming standard.






Related Posts Plugin for WordPress, Blogger...