• Headlines
  • News
  • Lifestyle
  • Opinion
  • Sports
Tempo - The Nation's Fastest Growing Newspaper
  • Home
  • Business
  • Entertainment
    • Alamin Kay Kuya Kim
    • Basta Everyday Happy
    • First Timer
    • Highspeed
    • Kampupot
    • Mouthful
    • Movies
    • Seeing Double
    • Timing
    • Trailer
  • Headlines
  • Lifestyle
    • Arts and Culture
    • Automotive
    • Fashion
    • Food
    • Health
    • People
    • Pets/Animal
    • Plants Flowers Trees
    • Tech Lifestyle
    • Tech News
    • Technology
    • Travel/Places
  • News
    • Local
    • Main
    • News Roundup
      • New Roundup
        • Featured
        • Metro News
        • Regional
        • Regional News
        • World News
    • Offbeat
    • Uncategorize
  • News in Photo
  • Opinion
    • Alex-syon of the Day
    • Always Chink Positive
    • Dear Inang Mahal
    • Echoes From
    • Editorial
    • Firing Line
    • Inspire and Equip!
    • Medium Rare
    • Of Trees and Forest
    • Poli-views
    • Reflections Today
    • Speaking Out
    • Special Report
    • That’s The Spirit
    • The Sexy Mind Answers
    • This Is On Me
    • Word Alive
  • Sports
    • Athletics
    • Baseball
    • Basketball
      • ABL
      • FIBA
      • MPBL
      • NBA
      • NCAA
      • PBA
      • UAAP
    • Billiards
    • Bowling
    • Boxing
      • Donaire
      • Pacquiao
    • Chess
    • Cycling
    • Football
      • NFL
    • Golf
    • karate
    • MMA
      • ONE Championship
      • UFC
    • Olympics
    • SEA Games
    • Silip
    • Soccer
    • Taekwondo
    • Tennis
    • The Dugout
    • Throwback
    • Volleyball
    • Wrestling
  • World
No Result
View All Result
  • Home
  • Business
  • Entertainment
    • Alamin Kay Kuya Kim
    • Basta Everyday Happy
    • First Timer
    • Highspeed
    • Kampupot
    • Mouthful
    • Movies
    • Seeing Double
    • Timing
    • Trailer
  • Headlines
  • Lifestyle
    • Arts and Culture
    • Automotive
    • Fashion
    • Food
    • Health
    • People
    • Pets/Animal
    • Plants Flowers Trees
    • Tech Lifestyle
    • Tech News
    • Technology
    • Travel/Places
  • News
    • Local
    • Main
    • News Roundup
      • New Roundup
        • Featured
        • Metro News
        • Regional
        • Regional News
        • World News
    • Offbeat
    • Uncategorize
  • News in Photo
  • Opinion
    • Alex-syon of the Day
    • Always Chink Positive
    • Dear Inang Mahal
    • Echoes From
    • Editorial
    • Firing Line
    • Inspire and Equip!
    • Medium Rare
    • Of Trees and Forest
    • Poli-views
    • Reflections Today
    • Speaking Out
    • Special Report
    • That’s The Spirit
    • The Sexy Mind Answers
    • This Is On Me
    • Word Alive
  • Sports
    • Athletics
    • Baseball
    • Basketball
      • ABL
      • FIBA
      • MPBL
      • NBA
      • NCAA
      • PBA
      • UAAP
    • Billiards
    • Bowling
    • Boxing
      • Donaire
      • Pacquiao
    • Chess
    • Cycling
    • Football
      • NFL
    • Golf
    • karate
    • MMA
      • ONE Championship
      • UFC
    • Olympics
    • SEA Games
    • Silip
    • Soccer
    • Taekwondo
    • Tennis
    • The Dugout
    • Throwback
    • Volleyball
    • Wrestling
  • World
No Result
View All Result
Tempo - The Nation's Fastest Growing Newspaper
No Result
View All Result
Home Lifestyle Tech News

Cyberthreats to financial institutions in 2019: overview and predictions

Tempo Online by Tempo Online
December 30, 2018
in Tech News
3
The emergence of new groups due to the fragmentation of Cobalt/Carbnal and Fin7: new groups and new geography

The emergence of new groups due to the fragmentation of Cobalt/Carbnal and Fin7: new groups and new geography

The emergence of new groups due to the fragmentation of Cobalt/Carbnal and Fin7: new groups and new geography
The emergence of new groups due to the fragmentation of Cobalt/Carbnal and Fin7: new groups and new geography

The past year has been extremely eventful in terms of the digital threats faced by financial institutions — cybercrime groups have used new infiltration techniques and the geography of attacks has become more extensive.

Despite this, let’s start the review with a positive trend: in 2018, police arrested a number of well-known cybercrime group members responsible for Carbanak/Cobalt and Fin7, among others. These groups have been involved in attacks on dozens, if not hundreds of companies and financial institutions around the world.

Unfortunately, the arrest of group members including the leader of Carbanak did not lead to a complete halt in activities – in fact, it seemingly started the process of splitting the groups into smaller cells.

The most active actor of 2018 was Lazarus. This group is gradually expanding its arsenal of tools and looking for new targets. The area of interest today includes banks, fintech companies, crypto-exchanges, PoS (point-of-sale) terminals, ATMs, and in terms of geography, we have recorded infection attempts in dozens of countries, most of which are located in Asia, Africa, and Latin America.

At the end of last year, we noted that young fintech companies and crypto-exchanges are at a higher risk, due to the immaturity of their security systems. This certain type of companies was targeted most often. The most creative attack seen in 2018, from our point of view, was AppleJeus, which targeted cryptocurrency traders. In this case, criminals created special software that looked legitimate and carried out legitimate functions. However, the program also uploaded a malicious update that turned out to be a backdoor. This is a new type of attack, which infects its targets via the supply chain.

Continuing the topic of supply chain attacks, it is worth mentioning the MageCart group, which, by infecting website payment pages (including those of large companies such as British Airways) was able to access a huge amount of payment card data this year. This attack was even more effective because the criminals chose an interesting target – Magento, which is one of the most popular platforms for online stores. Using vulnerabilities in Magento, criminals were able to infect dozens of sites in a technique that is likely to be used by several other groups.

We should also note the development of ATM malware families. In 2018, Kaspersky Lab specialists discovered six new families, meaning that there are now more than 20 of this kind. Some ATM malware families have also evolved: for example, the Plotus malware from Latin America has been updated to a new version, Peralda, and has gained new functionality as a result. The greatest damage associated with attacks on ATMs was caused by infections from internal banking networks, such as FASTCash and ATMJackPot, which allowed attackers to reach thousands of ATMs.

2018 also saw attacks on organizations that use banking systems. Firstly, our machine learning-based behavioral analysis system detected several waves of malicious activity related to the spread of the Buhtrap banking Trojan this year, as attackers embedded their code in popular news sites and forums. Secondly, we detected attacks on the financial departments of industrial companies, where payments of hundreds of thousands of dollars would not cause much suspicion. Often in the final stages of attacks like this, attackers install remote administration tools on infected computers such as RMS, TeamViewer, and VNC.

Before giving our forecasts for 2019, let’s see how accurate our forecasts for 2018 turned out to be:

  • Attacks made through the underlying blockchain technologies of financial systems implemented by the financial institutions themselves – This did not happen in the financial field but was seen in the online casino sector.
  • More supply chain attacks in the financial world – Yes
  • Attacks on mass media (in general, including Twitter accounts, Facebook pages, telegram channels and more) including hacks and manipulation for getting financial profit through stock/crypto exchange trade – Yes
  • ATM malware automation – Yes. For example, there are malicious programs that immediately give money to attackers.
  • More attacks on crypto exchange platforms – Yes
  • A spike in traditional card fraud due to the huge data breaches that happened in the previous year – no
  • More nation-state sponsored attacks against financial organizations – Yes
  • The inclusion of fintechs and mobile-only users in attacks: a fall in the number of traditional PC-oriented internet banking Trojans, with novice mobile banking users becoming the new prime target for criminals – Yes. In particular, some banking Trojans stopped attacking users of online banking on PCs, while the number of Trojans attacking users of mobile devices has more than doubled over the past year.

Predictions for 2019

  • The emergence of new groups due to the fragmentation of Cobalt/Carbnal and Fin7: new groups and new geography

The arrest of leaders and separate members of major cybercrime groups has not stopped these groups from attacking financial institutions. Next year, we will most likely see the fragmentation of these groups and the creation of new ones by former members, which will lead to the intensification of attacks and the expansion of the geography of potential victims.

At the same time, local groups will expand their activities, increasing quality and scale. It is reasonable to assume that some members of the regional groups may contact former members of the Fin7 or Cobalt group to facilitate access to regional targets and gain new tools with which they can carry out attacks.

  • The first attacks through the theft and use of biometric data

Biometric systems for user identification and authentication are being gradually implemented by various financial institutions, and several major leaks of biometric data have already occurred. These two facts lay the foundation for the first POC (proof-of-concept) attacks on financial services using leaked biometric data.

  • The emergence of new local groups attacking financial institutions in the Indo-Pakistan region, South-East Asia and Central Europe

The activity of cybercriminals in these regions is constantly growing: the immaturity of protective solutions in the financial sector and the rapid spread of various electronic means of payment among the population and companies in these regions are contributing to this. Now, all the prerequisites exist for the emergence of a new center for financial threats in Asia, in addition to the three already in Latin America, the Korean peninsula and the ex-USSR.

  • Continuation of the supply-chain attacks: attacks on small companies that provide their services to financial institutions around the world

This trend will remain with us in 2019. Attacks on software providers have proven effective and allowed attackers to gain access to several major targets. Small companies (that supply specialized financial services for the larger players) will be jeopardized first, such as the suppliers of money transfer systems, banks, and exchanges.

  • Traditional cybercrime will focus on the easiest targets and bypass anti-fraud solutions: replacement of PoS (point-of-sale) attacks with attacks on systems accepting online payments

Next year, in terms of threats to ordinary users and stores, those who use cards without chips and do not use two-factor authorization of transactions will be the most at risk. The malicious community has focused on some simple goals that are easy to monetize. However, this does not mean that they do not use any complex techniques. For example, to bypass anti-fraud systems, they copy all computer and browser system settings. On the other hand, this cybercriminal behavior will mean that the number of attacks on PoS terminals will decrease, and they will move towards attacks on online payment platforms instead.

  • The cybersecurity systems of financial institutions will be bypassed using physical devices connected to the internal network

Due to the lack of physical security and the lack of control over connected devices in many networks, cybercriminals will more actively exploit situations where a computer or mini-board can be installed, specifically configured to steal data from the network and transfer the information using 4G/LTE modems.

Attacks like this will provide cybergangs with an opportunity to access various data, including information about the customers of financial institutions, as well as the network infrastructure of financial institutions.

  • Attacks on mobile banking for business users

Mobile applications for business are gaining popularity, which is likely to lead to the first attacks on their users. There are enough tools for this, and the possible losses that businesses incur are much higher than the losses incurred when individuals are attacked. The most likely attack vectors are attacks at the Web API level and through the supply chain.

  • Advanced social engineering campaigns targeting operators, secretaries and other internal employees in charge of wires: result of data leaks

Social engineering is particularly popular in some regions, for example, in Latin America. Cybercriminals keep targeting specific people in companies and financial institutions to make them wire big sums of money. Due to a high amount of data leakages previous years this type of attacks becomes more effective since criminals are able to use leaked internal information about the targeted organization to make their messages look absolutely legit. The main idea remains the same: they make these targets believe that the financial request has come from business partners or directors. These techniques use zero malware but demonstrate how targeted social engineering gets results and will become more powerful in 2019. This includes attacks like “simswap”.

Tags: Cybercrimefinancial institutionsgroup memberskaspersky lablatin americasupply chainSupply chain attacks
Previous Post

Travel light

Next Post

‘The Kid Who Would Be King’ Official Trailer revealed

Next Post
Angus Imrie, Louis Serkis, Tom Taylor, Rhianna Doris, Dean Chaumoo in THE KID WHO WOULD BE KING

'The Kid Who Would Be King' Official Trailer revealed

Comments 3

  1. acquips says:
    3 months ago

    C, Mutation analysis of pVEGFR2E in ZR 75 cells buy cialis online india Moreover, these studies had a common limitation, in that prognosis was evaluated without considering trastuzumab treatment

    Reply
  2. inherrori says:
    1 month ago

    5- 2 per month cialis 5mg best price I understand there are failsafe methods, such as nolva throughout the entire cycle, clomid AND nolva for PCT, etc etc

    Reply
  3. taurant says:
    5 days ago

    cialis without a prescription Ideally, this training could be incorporated into clinical trial networks to help ensure uniformity and compliance

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

ADVERTISEMENT
ADVERTISEMENT
  • 2017 NBA Draft Order and Results
  • 37 NBP prisoners get diplomas
  • 3rd Nobleland Cup Championship Results and Scoreboard
  • 4th Nobleland Open Results and Scoreboard
  • Businessman’s car robbed
  • Cop arrested for gunrunning
  • Customs men lauded
  • DOST- Science Education Institute Scholars [A]
  • DOST- Science Education Institute Scholars [B]
  • DOST- Science Education Institute Scholars [C]
  • DOST- Science Education Institute Scholars [D]
  • DOST- Science Education Institute Scholars [E]
  • DOST- Science Education Institute Scholars [F]
  • DOST- Science Education Institute Scholars [G]
  • DOST- Science Education Institute Scholars [H]
  • DOST- Science Education Institute Scholars [I]
  • DOST- Science Education Institute Scholars [J]
  • DOST- Science Education Institute Scholars [K]
  • DOST- Science Education Institute Scholars [L]
  • DOST- Science Education Institute Scholars [M]
  • DOST- Science Education Institute Scholars [N]
  • DOST- Science Education Institute Scholars [O]
  • DOST- Science Education Institute Scholars [P]
  • DOST- Science Education Institute Scholars [Q]
  • DOST- Science Education Institute Scholars [R]
  • DOST- Science Education Institute Scholars [S]
  • DOST- Science Education Institute Scholars [T]
  • DOST- Science Education Institute Scholars [U]
  • DOST- Science Education Institute Scholars [V]
  • DOST- Science Education Institute Scholars [W]
  • DOST- Science Education Institute Scholars [Y]
  • DOST- Science Education Institute Scholars [Z]
  • Duterte thanks troops for securing country
  • Epaper
  • Ex-Coast guard officer kills wife before taking own life
  • Fake traffic enforcer nabbed for extortion
  • Frontend Submission
  • hm
  • It’s a girl!
  • Knowledge of the mysteries of the kingdom of God
  • Kris off to Singapore for medical treatment
  • List of 2018 DOST – Science Education Institute Scholars
  • New storm set to enter PH
  • No excuses for E-Painters
  • Public warned vs 5 food products
  • Sample Page
  • Shortcodes
  • Student found naked waist down in Cavite
  • Tempo Home – 2021
  • Testing the Elements
  • Page Templates
  • Media Gallery

© 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

No Result
View All Result
  • 2017 NBA Draft Order and Results
  • 37 NBP prisoners get diplomas
  • 3rd Nobleland Cup Championship Results and Scoreboard
    • 37th PBA Open Championship Results and Scoreboard
      • 37th PBA Open Championship Results [Mixed Classified]
      • 37th PBA Open Championship Results [Mixed Open]
      • 37th PBA Open Championship Results [Mixed Seniors]
      • 37th PBA Open Championship Results [Mixed Youth]
    • Mixed All Events
    • Mixed Doubles Event
    • Mixed Singles Event
    • Mixed Team Event
  • 4th Nobleland Open Results and Scoreboard
    • 4th Nobleland Open [Mixed Associate]
    • 4th Nobleland Open [Mixed Graded]
    • 4th Nobleland Open [Mixed Open]
    • 4th Nobleland Open [Mixed Seniors]
    • 4th Nobleland Open [Mixed Youth]
  • Businessman’s car robbed
  • Cop arrested for gunrunning
  • Customs men lauded
  • DOST- Science Education Institute Scholars [A]
  • DOST- Science Education Institute Scholars [B]
  • DOST- Science Education Institute Scholars [C]
  • DOST- Science Education Institute Scholars [D]
  • DOST- Science Education Institute Scholars [E]
  • DOST- Science Education Institute Scholars [F]
  • DOST- Science Education Institute Scholars [G]
  • DOST- Science Education Institute Scholars [H]
  • DOST- Science Education Institute Scholars [I]
  • DOST- Science Education Institute Scholars [J]
  • DOST- Science Education Institute Scholars [K]
  • DOST- Science Education Institute Scholars [L]
  • DOST- Science Education Institute Scholars [M]
  • DOST- Science Education Institute Scholars [N]
  • DOST- Science Education Institute Scholars [O]
  • DOST- Science Education Institute Scholars [P]
  • DOST- Science Education Institute Scholars [Q]
  • DOST- Science Education Institute Scholars [R]
  • DOST- Science Education Institute Scholars [S]
  • DOST- Science Education Institute Scholars [T]
  • DOST- Science Education Institute Scholars [U]
  • DOST- Science Education Institute Scholars [V]
  • DOST- Science Education Institute Scholars [W]
  • DOST- Science Education Institute Scholars [Y]
  • DOST- Science Education Institute Scholars [Z]
  • Duterte thanks troops for securing country
  • Epaper
  • Ex-Coast guard officer kills wife before taking own life
  • Fake traffic enforcer nabbed for extortion
  • Frontend Submission
  • hm
  • It’s a girl!
  • Knowledge of the mysteries of the kingdom of God
  • Kris off to Singapore for medical treatment
  • List of 2018 DOST – Science Education Institute Scholars
  • New storm set to enter PH
  • No excuses for E-Painters
  • Public warned vs 5 food products
  • Sample Page
  • Shortcodes
  • Student found naked waist down in Cavite
  • Tempo Home – 2021
  • Testing the Elements
  • Page Templates
    • 2017 PBA Philippine Cup Standings
      • 2017 PBA Draft Board Results
    • Archives
    • Classic Blog Format
    • Left Sidebar
    • Sitemap
    • Widgetized
  • Media Gallery
    • UAAP Season 79 Men’s Senior Basketball Standings

© 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.