Channel News and Analysis - Channel Insider
Empowering the next generation Channel
 

Sponsored Links
  • Get up and running in as quickly as 30 days with BI. Learn how today.
  • FREE Securing Smartphones & Tablets for Dummies Book from Sophos
  • 5 New Technologies That Will Change Enterprise ITAdvertisement
  • Build an IT Infrastructure That Delivers the Future

  •  

    RSA Catches Financial Phishing Kit

    in Channel News and Analysis



    Article Rating:starstarstarstarstar / 0
    Article Views: 1474

    The security company identifies a new phishing kit that is being sold and used online by fraudsters who are targeting financial organizations.

    Rate This Article:
    Add This Article To:
    RSA, The Security Division of EMC, announced Jan. 10 that it has identified a new phishing kit that was being sold and used online by hackers to target users' personal information in real time.

    The phishing kit, known as a Universal Man-in-the-Middle Phishing Kit, is meant to help online hackers create attacks involving financial organizations by enabling the hacker to create a fake URL through a user-friendly online interface. The fraudulent URL communicates with the legitimate Web site of the targeted organization in real time.

    The target receives a standard phishing e-mail, and if the target clicks on the link, he or she is sent to the fake URL. The target thinks that he or she is working with content from the legitimate Web site, but in fact, the fake URL allows hackers to access the targets' personal information, RSA said.

    Phishers are increasingly targeting financial institutions. Click here to read more.

    "As institutions put additional online security measures in place, inevitably the fraudsters are looking at new ways of duping innocent victims and stealing their information and assets," Marc Gaffan, director of marketing for Consumer Solutions at RSA Security, based in Bedford, Mass., told eWEEK.

    The new phishing kit was uncovered by RSA's AFCC (Anti-Fraud Command Center), a 24/7 team of 40 trained fraud analysts that work to mitigate online fraud.

    The AFCC handled the kit by using an extensive monitoring and detection network, a broad blocking network and its site-shutdown capabilities.

    "Using various technologies and procedures, the AFCC detects phishing attacks, analyzes them and works to shut them down on behalf of our FraudAction customers," Gaffan said.

    For advice on how to secure your network and applications, as well as the latest security news, visit Ziff Davis Internet's Security IT Hub.

    RSA analysts said the phishing kit has two main benefits for hackers. One, the hacker does not have to purchase or prepare a custom phishing kit for the organization being targeted, and two, the attack can intercept any type of credentials that are sent in to the site after the user has logged into his or her account.

    "While these types of attacks are still considered next-generation, we expect them to become more widespread over the course of the next 12-18 months," Gaffan said.

    However, Gaffan said the AFCC will continue to shut down these kinds of attacks.

    "The analysts at the AFCC work around the clock on behalf of the banks, so the banks can outsource the headache of detecting, shutting down and dealing with attacks in general," Gaffan said. "The AFCC has vast experience in the industry and deep expertise in online fraud and banks can benefit from that and enjoy the economies of scale."

    The AFCC service varies in price depending on the type of service a bank selects as well as the size of the bank.

    Check out eWEEK.com's Security Center for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at Ryan Naraine's eWEEK Security Watch blog.




    comments dic


     
     
    >>> More Channel News and Analysis Articles          >>> More By Patrick Hoffman
     


     



    channel chatter


    HTML PLAIN TEXT

    Keep on top of news for VARs and Resellers with CI's Weekly Newsletter and Alerts.


    [ci] feeds
    XML
    Add Channel News, Product Reviews, Trends and Analysis to your RSS newsreader or My Yahoo!


     


    CHANNEL SPONSORED RESOURCE CENTER
     
     
     
    Start the New Year with business intelligence—it’s a smart move
    Join us on February 1 for an encore rebroadcast at either 5 am or 12 noon EST and discover how business intelligence (BI) supports companies in uncertain business and economic climates. Get expert advice on how to create a strategy that fits your organization's needs and budget and see how quickly it can pay for itself.
    Click Here
     
    Security and Availability Essentials for Running Your Business in the Cloud
    Are you moving to the cloud? Find out what every IT professional should know about security and availability before moving to the cloud. Hear what a security provider’s own CSO has to say.
    Watch Video
    A new algorithm automatically identifies relationships between variables to help reduce researcher prejudice.
    Click HereAdvertisement