NEWS / WINDOWS

RSA Discovers Universal Phishing Kit

13 Jan, 2007, 2:08 pm IST | by Sharon Khare | Windows

RSA, The Security Division of EMC, provider of information infrastructure, has announced that its 24x7 Anti-Fraud Command Center (AFCC) has uncovered a new phishing kit being sold and used online by fraudsters.

This new kit, a Universal Man-in-the-Middle Phishing Kit, is designed to facilitate new and sophisticated attacks against global organizations in which the victims communicate with a legitimate web site via a fraudulent URL set by the fraudster. This allows the fraudster to capture victims' personal information in real-time.

RSA's analysts researched and analyzed a demo of the kit that was being offered as a free trial on one of the online fraudster forums that the AFCC monitors regularly.

Using the Universal Man-in-the-Middle Phishing Kit, the fraudster creates a fraudulent URL via a simple and user-friendly online interface. This URL communicates with the legitimate website of the targeted organization in real- time - whether it is the online banking site of a financial institution, the order tunnel of an ecommerce company, or any other such business transacting with its users online. The victim receives a "standard" phishing email, and when clicking on the link s/he is directed to the fraudulent URL. The victim then interacts with genuine content from the legitimate website - which has been "imported" by the attack into the phishing URL - thus allowing the fraudster seamless, invisible and immediate access to the victim's personal information.

It is a "universal" phishing kit, meaning it can easily be configured per target. Fraudsters who want to initiate a phishing attack do not have to purchase or prepare a custom phishing kit for each target. Once they acquire and operate this kit, the attack can be configured to "import" pages from any target website. Unlike standard phishing attacks, which only collect specific requested data (typically login and card-related credentials), this attack is designed to intercept any type of credentials submitted to the site after the victim has logged into his account as well.

"As institutions put additional online security measures in place, inevitably the fraudsters are looking at new ways of duping innocent victims and stealing their information and assets. While these types of attacks are still considered 'next generation,' we expect them to become more widespread over the course of the next 12-18 months," said Marc Gaffan, director of marketing, Consumer Solutions at RSA. "We are working with many organizations to ensure they are positioned to withstand whatever threats fraudsters may create. Some of these organizations have already deployed various layers of protection and others are in the process of strengthening their security."

Tags: RSA , Phishing

RELATED STORIES

VeriSign got hacked in 2010, might have risked Internet DNS

VeriSign got hacked in 2010, might have risked Internet DNS

VeriSign is a company that’s been around, since ages and are known best of their security solutions. Back ...

RSA to Replace All SecurID Tokens

Defense Contractor Lockheed Martin Gets Hacked

'Gmail' storage upgrade phishing mail steals user logins and passwords

Agari's anti-phishing initiative gets major enlisters

Chinese Hackers Make a Failed Attempt to Disrupt Gmail

Watch Out, Facebook App Promising to Show you Pageviews is Evil

RSA Animate - The Power of Networks

22 May, 2012, 12:55 am IST

RSA Animate - The Power of Networks

RSA Animate - Changing Education Paradigms

14 Oct, 2010, 03:51 pm IST

RSA Animate - Changing Education Paradigms

RSA Animate - Smile or Die

17 Mar, 2010, 10:38 pm IST

RSA Animate - Smile or Die

 

OPINIONS

Padmini Harchandrai

The latest "should they-shouldn't they" event with Facebook is the lift of the minimu...

MORE OPINIONS

Leaked Images, Availability, Pricing,
Specs, Pre-order

features

Top 5 free all-in-one messengers for Windows

Top 5 free all-in-one messengers for Windows

The number of instant messaging services have exploded, since the first...

By Rossi Fernandes

Project Darpan: Digitizing Indian local languages

Project Darpan: Digitizing Indian local languages

Compared to the relatively slow adoption rate of the traditional PC, that...

By Naina Khedekar

Top 10 tips for Internet Explorer 9

Top 10 tips for Internet Explorer 9

Microsoft’s browser Internet Explorer has been around a while and things

By Tech2

MORE FEATURES

Ainol Novo 7 Paladin Review

Allan Crispino

Mon May 28, 12:33:12

Ainol Novo 7 Paladin Review

Karan Shah

Mon May 28, 12:26:13

Samsung confirms S III's India launch on May 31

Hardik Shah

Mon May 28, 11:47:09

MORE DISCUSSIONS