
Zombie machines, money mules and cash-out criminals
By Nick Heath
Published: 31 October 2008 12:35 GMT
Cloud computing crimeware means networks of zombie machines can be hired to steal online banking details for as little as $299 per month.
Fraud-as-a-service is opening up computer crime to people with no technical expertise warned Uri Rivner, head of new technology at security company RSA.
Security from A to Z
Click on the links below to find out more...
A is for Antivirus
B is for Botnets
C is for CMA
D is for DDoS
E is for Extradition
F is for Federated identity
G is for Google
H is for Hackers
I is for IM
J is for Jaschan (Sven)
K is for Kids
L is for Love Bug
M is for Microsoft
N is for Neologisms
O is for Orange
P is for Passwords
Q is for Questions
R is for Rootkits
S is for Spyware
T is for Two-factor authentication
U is for USB sticks/devices
V is for Virus variants
W is for Wi-fi
X is for OS X
Y is for You
Z is for Zero-day
Speaking at the RSA Conference 2008 in London, Rivner laid the pricing bare, revealing how fraudsters offered botnet networks as a subscription service with patching and upgrades thrown in.
These networks could be tailored to infect other users' computers with malware, or to launch massive distributed denial of service attacks designed to take down computer systems.
Rivner said: "This is the danger with making this technology open to the mass market.
"Anybody can become a high-end online fraudster."
Malware is also being sold for both the high end and budget markets, from the $1,000 Zeus Trojan - a sophisticated Trojan that harvests data and entrenches itself in the system - down to $350 for the Limbo Trojan.
Rivner said the fraudsters usually split their roles between the "harvester", the hacker who writes and deploys the malware to steal the details, and a "cash-out" criminal who will handle the money.
Cash-out fraudsters use "money mules", who are often recruited unwittingly as "finance officers" working from home, to have the dirty money laundered through their account.
The ideal candidate will possess the following technical skills and experience:- • Microsoft Desktop Support • Hardware Builds, Installs ...
AntiMalware Researcher Graduate in computer sciences Experience in high-level programming languages (C, C++, C#) Knowledge of low level programming ...
In depth experience of working with Intrusion Detection (IDS), Threat Analysis and Malware & Trojan Research technologies and techniques are expected ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Is Your Enterprise Architected for Tomorrow's Growth?
Improving IT service delivery through an integrated approach to software asset management...
The Real Reason Executive Participation Creates IT Project Success
Information Management, BPM and Integration: Achieving Cost Efficiency in the Financial...
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
silicon.com staff Inbox: Social networking can help you secure a job Plus: Open source advocates hit back at CIOs and netbooks fail 'fit for work' test
Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead