Read + Write + Report
Home | Start a blog | About Orble | FAQ | Sites | Writers | Advertise | My Orble | Login

Hackers unleash next generation trojan against aussie banks

February 9th 2009 02:21

ANZ is warning its’ customers about a "Personal Details form" that appears to customers after they log on to the genuine ANZ website internet banking interface. The pop-up form is convincingly branded and features a seemingly genuine form with scroll down menus.
Previous trojan attacks typically try to redirect the user’s browser to a fake bank site, but this one operates when the user is in a session with the genuine bank website and the genuine online banking interface.
Sam Plowman, Head of Online Banking, ANZ, says the threat is contained on user’s computers and does not mean that that the ANZ website or internet banking interface has been compromised in any way.
“A trojan has affected a couple of our customer’s computers and uploads a form that is branded with ANZ and asking for personal details.”
“Subsequently we have put out an alert to constantly be aware of this type of attack.”
“The feedback I have from the e-crime groups is that this is wider than just ANZ, but unlike some of the others, we have decided last night, upon noticing the trojan, to put the alert on the website to maximize the amount of information we share with our customers to protect them as best as possible.”
Jeff McGeorge, Director of Brisbane based security vendor Markets-Alert says this attack is a step forward by the hackers.

“This is very clever, this is a new angle.

“What is happening is that the session between the user’s browser and the bank’s server is being compromised. Once you press a button on the ANZ web page, that is triggering a PHP script on your browser to make the page pop up.”
“If the user is logging in and then being redirected then that would be a real bugger – that would generally be showing that the bank’s web server is being owned,” said McGeorge.
“The script could be capturing all the information that the user is typing into the ANZ page, as well as the details they are typing into the bogus page.”

Although ANZ’s security alert says the bogus form appears to customers after they log on to internet banking, Sam Plowman denies that there has been any breach of the bank’s server or website.
“In no way whatsoever has there been any compromise of the internet banking site – it is a trojan loading within the user’s PC,” said Plowman
Plowman has no idea where this threat may have originated, but is not aware of any offshore institutions reporting similar attacks.
“Our internal team is currently investigating this and working with the external e-crime teams, we haven’t been briefed by them yet but no doubt at some stage we will be.”
Jeff McGeorge has some ideas about where the threat may be coming from.
“There have been a whole lot of retrenchments out of banks and financial institutions - disgruntled ex-IT staff, disgruntled ex-security staff, they know how the system works and the incentive is there to get some money.”

40
Vote


   
Subscribe to this blog 


Just this blog This blog and DailyOrble (recommended)

   

   


Add A Comment

To create a fully formatted comment please click here.


CLICK HERE TO LOGIN | CLICK HERE TO REGISTER

Name or Orble Tag
Home Page (optional)
Comments
Bold Italic Underline Strikethrough Separator Left Center Right Separator Quote Insert Link Insert Email
Notify me of replies
Notify extra people about this comment
Is this a private comment?
List the Email Addresses or Orble Tags of the people you would like to be notified about this comment


One per line max of 30

List the Email Addresses or Orble Tags of the people you would like to be notified about this private comment thread. Only the people in this list will be able to see or reply to your comment.


One per line max of 30

Your Name
(for the email going out to the above list, it can be different to your Orble Tag)
Your Email Address
(optional)
(required for reply notification)
Submit
More Posts
2 Posts
1 Posts
2 Posts
6 Posts dating from October 2008
Email Subscription
Receive e-mail notifications of new posts on this blog:
0

Jason Bryce's Blogs

123 Vote(s)
0 Comment(s)
3 Post(s)
249 Vote(s)
2 Comment(s)
8 Post(s)
38 Vote(s)
0 Comment(s)
1 Post(s)
Moderated by Jason Bryce
Copyright © 2006 2007 2008 On Topic Media PTY LTD. All Rights Reserved. Design by Vimu.com.
On Topic Media ZPages: Sydney |  Melbourne |  Brisbane |  London |  Birmingham |  Leeds     [ Advertise ] [ Contact Us ] [ Privacy Policy ]