tisdag 9 februari 2010
Låt it inspirera dig

Skriv ut TipsaKommentera

The Nordea hacker claims responsibility for other major attacks - Computer Sweden:

Meeting the Swedish bank hacker

Symantec security expert Per Hellqvist helped Computer Sweden track down the inventor of the Nordea-trojan.
Symantec security expert Per Hellqvist helped Computer Sweden track down the inventor of the Nordea-trojan.

The same Trojan that stole eight million Swedish kronor from the Nordea bank was also used for a major attack in Australia. This is confirmed by the hacker who calls himself "Corpse", a developer of advanced Trojans. Computer Sweden's reporter met him in an anonymous chat.

With the aid of security expert Per Hellqvist of Symantec, Sweden, Computer Sweden tracked the Russian-speaking hacker. Using a pseudonym, our reporter claimed to be interested in buying his own Trojan, tailored for attacking an internet bank. It was soon obvious that "Corpse" knows very well that his application is used for major Internet banking frauds.

The bank accounts broken into are selected at random: "It's like roulette," he says in broken English: "Some accounts have a million dollars, some have one dollar. You never know who gets infected."

CS: The Trojan that some people call Haxdoor, is that yours? Does it have the same functionality?

"Corpse": Yes, Haxdoor (there are so many varieties) is mine.

"Corpse" himself sells the Haxdoor Trojan under the name A311 Death. Haxdoor is the name given to it by virus protection software vendors.

CS: Have you heard about the Nordea attacks? That was Haxdoor, wasn't it?

"Corpse": Haxdoor and Nuclear Grabber (a Haxdoor version without a back door).

CS: Quite impressive. Is that the version that I could get for 3,000 dollars?

"Corpse": Yes, and ...

CS: And...

"Corpse": [Provides a URL to information about the attack in Australia.] That's Haxdoor too.

CS: I get that for 3,000 dollars?

"Corpse": Yes, it's the same version.


Computer Swedens reporter meets Corpse.

Those attacks against Internet banks that are reported are, according to "Corpse", only the top of an iceberg. Banks cover up most attacks - something that attackers appreciate.

CS: Cool. Any more examples of attacks using Haxdoor?

"Corpse": The banks try to cover up 99 percent of all attacks, because they do not want to scare their customers. :)

As soon as the money is cleared, the program will be delivered, and scripts for picking up stolen information, such as one-time scratch pad access codes to the Nordea Internet bank, will be installed. "Corpse" will assist - support is included in the price.

Our questions about previous customers and about the perpetrators of the Nordea fraud seem to make "Corpse" uncomfortable:

CS: This seems simple, but don't you need a lot of people to do this?

"Corpse": There is only one developer, and that's me.

CS: Yes, but I mean your customers. Like the Nordea attack - was that one person or a bigger group?

"Corpse": I don't know ... some work on their own, some in groups.

When our reporter pretends to be worried about getting caught, "Corpse" sounds reassuring. At 150 dollars a month, he can provide servers in China, Europe or in the USA where the stolen information will be stored. That way, the attacks will be impossible to trace.

"Corpse": I can buy servers or web hotels for you.

CS: OK, won't that get you into trouble. Maybe it's easier to run anonymous servers in Russia?

"Corpse": Not in Russia. USA, China or Europe...

CS: Your security is important to me, because if you're caught, I might get caught. Aren't you worried about the police?

"Corpse": Don't worry about the police. Just use anonymous VPN or Socks, and it will be alright. :)

Some versions of the Haxdoor Trojan can hide themselves in the operating system with rootkit functionality. That means they're invisible to most virus protection applications. "Corpse" confirms that the version he is hawking works like this. The virus protection program from Norman, which Nordea bought and provides its Internet banking customers with free of charge, he dismisses outright.

CS: Are you familiar with Norman Antivirus? They say it can detect Haxdoor on an infected computer.

"Corpse": Anti-virus applications can't find the undetectable version.

The Trojan includes a graphic user interface that the attacker can use for designing a tailormade attack on a specifik bank. "Corpse" confirms that the Trojan is activated when a specific phrase, such as "scratch code 1" appears on a web page. It picks up the information and forwards it. It's quite simple, he insists.

"Corpse": The interface is standard and requires no special skills. If you have any problems, I'll help.

Like any salesman, "Corpse" boasts about Haxdoors usefulness for successful bank frauds.

"Corpse": Yes, it will have rootkit and self-protection features.

CS: Good, how is it delivered?

"Corpse": As an rar or zip archive.

CS: By the way, will it also infect Vista? And how about older versions of Windows?

"Corpse": All versions are supported - Windows 98 (4/10/1998) and later.

CS: Including Vista?

"Corpse": Yes.

After one and a half hours of conversation, "Corpse" feels certain that the sale is in the bag, and that his intrusion program has made him another 3,000 dollars.

CS: This is very interesting. I need to do some planning, then I'll get back to you - OK?

"Corpse": OK.

CS: When are you usually online? We might be in different time zones.

"Corpse": 15-24 (GMT +0).

Translated by: Anders Lotsson.

Skriv ut TipsaKommentera
Artikelkommentatorerna ansvarar själva för sina inlägg
RSS Den här artikeln har 4 kommentarer:

Spännande! - (Woosh) 2007-01-26 16:48

jadu - (__Tedde__) 2007-01-26 19:23

jadu - (Lingen) 2007-01-26 22:50

jadu - (md2perpe) 2007-01-26 23:01

OBS! Denna artikel är mer än 60 dygn gammal och är därför stängd för vidare debatt.

Krönikan

Smileys med näsa? Stenålder!

Om paddor och poddar

CS dreglar över...

Under snedstrecket


Hett på CS just nu

- Computer Sweden:

Fyra snabba svar:
Ska alla elever ha en dator?

(4 kommentarer)


- Computer Sweden:

Konsumtion och miljö går ihop


- Computer Sweden:

"Du fattar ingenting"

(1 kommentar)




- Computer Sweden:

Han kräver lönsamhet
av alla webbprojekt

(1 kommentar)



- Computer Sweden:

Monsterpatch
till Windows

(29 kommentarer)


- Computer Sweden:

SAPs grundare
medger felaktigheter




- Computer Sweden:

Börsbuggen gav falska siffror


- Computer Sweden:

Supercomm går i graven


- Computer Sweden:

SAP har blivit enklare

(1 kommentar)


It-jättar ratar Sverige

Affärer & företag Den svenska elskatten är 56 gånger högre för en datahall än för en fabrik. Det främjar basindustrin men skrämmer bort it-bolagen.

(44 kommentarer)

Computer Sweden:

  1. Serverskatten på riksdagens bord

    Samhälle Camilla Lindberg, FP, kräver i en motion att it-företag inte ska missgynnas av energiskatten.

(13 kommentarer)

Computer Sweden:

  1. Ledare: Välkommen
    till 2000-talet

    Ledaren "Det är 'hål i huvudet' att inte ge serverhallarna gynnsamma skattevillkor"

(6 kommentarer)


- Computer Sweden:

Användarna rasar mot
Oracle - ännu en gång


- IT24:

Vinstmaskinen Tele2 tuggar på


- Computer Sweden:

Välkänd bugg i Flash
fortfarande inte fixad



Affärsfokus

- Computer Sweden:

Spendrups lockar med Iphone

(11 kommentarer)

Folk

- Computer Sweden:

Hennes jobb är att
försvara rättsstaten

(9 kommentarer)


Dagens krönikor

- Computer Sweden:

Smileys med näsa? Stenålder!

(2 kommentarer)


- Computer Sweden:

Miljon gånger mer i lön

(1 kommentar)


Opinion

- Computer Sweden:

"Du fattar ingenting"

(1 kommentar)


- Computer Sweden:

Ledare: Välkommen
till 2000-talet

(6 kommentarer)


- Computer Sweden:

Vi mår bra


Ledare

Låt it inspirera dig
Välkommen till 2000-talet

Efter jobbet


Missa inte

Bloggar

Experterna svarar

Kan jag kräva vikariatet?

Dagens ord

"Mpeg-4"

Community


Fyll på vår wiki

Tyck till om CS säkerhetsexperter

Prenumerera

Senaste nytt

Reklam

Nytt kompendium

Maximera utfallet av ditt projekt

Låt jobben komma till dig

Dagens fråga

Har du problem med applikationshantering på företaget?

@Senior_it Att IT-folket inte kan förklara saker tydlig svenska - t ex vad är applikationshantering?

@senior_it ställde en fråga. Så svarade jag: På lång sikt är publikt det rätta

@senior_it ställde en fråga. Så svarade jag: Känns säkrare med privata moln!

Utvalda whitepaper

Så ställer du krav på ett IT-system
Förbered för affärskritisk SOA genom ny IT-styrning
Så handskas du med de 5 svåraste NAC-utmaningarna

Nya whitepapers och webcasts

Partnerzon från Oracle


Prenumerera nu

Prova 1 månad kostnadsfritt

Nyhetsbrev

CS nyhetsbrev varje dag


hittar du här.

 
Tekniken under decenniet som gått

"Utmaningen blir att använda tekniken på ett smartare sätt."

Läs krönikan av
Johan Ekesiöö på IBM.

Utbildningsguide

Utbildningsguiden

Nytt från PDF-shopen

Pressmed. från företag

Kundcase från företag

Kurs&EventKalendern

Aktuella events från IDG

Senaste nytt från IT24.se

CS Hemma

Senaste tidningen

Kompendium

Koll på licenserna?
Det mobila kontoret
- snart en självklarhet

För annonsörer

RSS-flöden

Nyhetsbrev
Dagliga
Veckobrev
Affärer & Företag
Affärssystem
CSjobb
Språksamt



Kontakta oss

Ring till 08-453 60 00.
Skicka gärna e-post till: cs@idg.se

Postadressen är:
Computer Sweden 106 78 Stockholm

Twitter:
@ComputerSweden, @CSDagensOrd

Om tidningen




AdtechSynpunkter på sajten? Kontakta Linus Larsson | Kontakta CS redaktion | Policy om personuppgifter & copyrightinfo
Karlbergsv. 77 106 78 Stockholm Tel: 08-453 60 00 Karta | Copyright © 1996-2010 International Data Group