Top Banner
1 © Copyright 2011 EMC Corporation. All rights reserved. “The trick is to stop thinking of it as ‘your’ money” - IRS Technion Security Summer School 2012 Etay Maor Research Lab Manager [email protected]
15

“The trick is to stop thinking of it as ‘your’ money” - IRStce.webee.eedev.technion.ac.il/wp-content/uploads/sites/8/2015/02/... · “The trick is to stop thinking of it

Mar 14, 2018

Download

Documents

tranhanh
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: “The trick is to stop thinking of it as ‘your’ money” - IRStce.webee.eedev.technion.ac.il/wp-content/uploads/sites/8/2015/02/... · “The trick is to stop thinking of it

1 © Copyright 2011 EMC Corporation. All rights reserved.

“The trick is to stop thinking

of it as ‘your’ money” - IRS

Technion Security Summer School 2012

Etay Maor

Research Lab Manager

[email protected]

Page 2: “The trick is to stop thinking of it as ‘your’ money” - IRStce.webee.eedev.technion.ac.il/wp-content/uploads/sites/8/2015/02/... · “The trick is to stop thinking of it

2 © Copyright 2011 EMC Corporation. All rights reserved.

1 2

6 5

RDP MITM Attack Scheme

Page 3: “The trick is to stop thinking of it as ‘your’ money” - IRStce.webee.eedev.technion.ac.il/wp-content/uploads/sites/8/2015/02/... · “The trick is to stop thinking of it

3 © Copyright 2011 EMC Corporation. All rights reserved.

VNC/RDP

Page 4: “The trick is to stop thinking of it as ‘your’ money” - IRStce.webee.eedev.technion.ac.il/wp-content/uploads/sites/8/2015/02/... · “The trick is to stop thinking of it

4 © Copyright 2011 EMC Corporation. All rights reserved.

What Else Are Fraudsters Up To?

• Citadel – THE latest version of Zeus

• Acknowledge the community’s requests

• Modules include: – All previous Zeus components – Video recorder – Auto CMD (“This is a good feature to have when analyzing a

company’s internal structure”) – DNS redirection (“AVs, Banks”) – “Important: Our software does not work on Russian-language systems.

If a Russian or Ukrainian layout is detected, the bot terminates. This is done to prevent installs on CIS systems. You may disagree, but that’s taboo for us.”

Page 5: “The trick is to stop thinking of it as ‘your’ money” - IRStce.webee.eedev.technion.ac.il/wp-content/uploads/sites/8/2015/02/... · “The trick is to stop thinking of it

5 © Copyright 2011 EMC Corporation. All rights reserved.

Citadel

Page 6: “The trick is to stop thinking of it as ‘your’ money” - IRStce.webee.eedev.technion.ac.il/wp-content/uploads/sites/8/2015/02/... · “The trick is to stop thinking of it

6 © Copyright 2011 EMC Corporation. All rights reserved.

Citadel + Ransomware

Page 7: “The trick is to stop thinking of it as ‘your’ money” - IRStce.webee.eedev.technion.ac.il/wp-content/uploads/sites/8/2015/02/... · “The trick is to stop thinking of it

7 © Copyright 2011 EMC Corporation. All rights reserved.

Mobile Vulnerabilities (POC)

– Insecure data storage

– HTML Injection

– Sensitive information disclosure

– Broken Cryptography

– And more…

• Source: OWASP Mobile Security Project

Page 8: “The trick is to stop thinking of it as ‘your’ money” - IRStce.webee.eedev.technion.ac.il/wp-content/uploads/sites/8/2015/02/... · “The trick is to stop thinking of it

8 © Copyright 2011 EMC Corporation. All rights reserved.

Portals, Redirectors and ATMs…O My…

Page 9: “The trick is to stop thinking of it as ‘your’ money” - IRStce.webee.eedev.technion.ac.il/wp-content/uploads/sites/8/2015/02/... · “The trick is to stop thinking of it

9 © Copyright 2011 EMC Corporation. All rights reserved.

Citadel Mobile Malware

Page 10: “The trick is to stop thinking of it as ‘your’ money” - IRStce.webee.eedev.technion.ac.il/wp-content/uploads/sites/8/2015/02/... · “The trick is to stop thinking of it

10 © Copyright 2011 EMC Corporation. All rights reserved.

Citadel Mobile Malware

Page 11: “The trick is to stop thinking of it as ‘your’ money” - IRStce.webee.eedev.technion.ac.il/wp-content/uploads/sites/8/2015/02/... · “The trick is to stop thinking of it

11 © Copyright 2011 EMC Corporation. All rights reserved.

Citadel Mobile Malware

Page 12: “The trick is to stop thinking of it as ‘your’ money” - IRStce.webee.eedev.technion.ac.il/wp-content/uploads/sites/8/2015/02/... · “The trick is to stop thinking of it

12 © Copyright 2011 EMC Corporation. All rights reserved.

Trojan Evasion

Page 13: “The trick is to stop thinking of it as ‘your’ money” - IRStce.webee.eedev.technion.ac.il/wp-content/uploads/sites/8/2015/02/... · “The trick is to stop thinking of it

13 © Copyright 2011 EMC Corporation. All rights reserved.

Trojan Evasion

Page 14: “The trick is to stop thinking of it as ‘your’ money” - IRStce.webee.eedev.technion.ac.il/wp-content/uploads/sites/8/2015/02/... · “The trick is to stop thinking of it

14 © Copyright 2011 EMC Corporation. All rights reserved.

XaaS

Page 15: “The trick is to stop thinking of it as ‘your’ money” - IRStce.webee.eedev.technion.ac.il/wp-content/uploads/sites/8/2015/02/... · “The trick is to stop thinking of it

15 © Copyright 2011 EMC Corporation. All rights reserved.

Security Awareness 101