SlideShare une entreprise Scribd logo
1  sur  72
Social Engineering in Banking Trojans
Attacking the weakest link
Jose Miguel Esparza
Mikel Gastesi
Agenda
• Social Engineering??
• Social Engineering + Malware
• HTML Injections
• Underground Market
• Solutions??
Social Engineering??
• The art of…
– … knowing how to handle people
Social Engineering??
• …or how to manipulate them
Social Engineering??
• …to Achieve an Objective
– Information gathering
– Buildings / Rooms access
– Power
– Material possessions
– Others: flirting, favors…
Social Engineering??
• …to Achieve an Objective
– Information gathering
– Buildings / Rooms access
– Power
– Material possessions
– Others: flirting, favors (sexual or not)…
• How?
– Face to face
– Phone / SMS
– Mail
– …
• Used by
– Politicians
– Salesmen
– Delinquents / Fraudsters
– You and me
Social Engineering??
Social Engineering??
Social Engineering??
• Take advantage of human nature
– Feelings / emotions / state of mind
– Behavior / personality
Social Engineering??
• Take advantage of human nature
– Feelings / emotions / state of mind
• Sadness
• Fear
• Rancor
• Embarrassment
• Happiness
• Love
• Hope
– Behavior / personality
Social Engineering??
• Take advantage of human nature
– Feelings / emotions / state of mind
– Behavior / personality
• Curiosity
• Inocence
• Honesty
• Generosity
• Gratitude
• Avarice
Social Engineering??
• Take advantage of human nature
– Feelings / emotions / state of mind
– Behavior / personality
• Tendency to trust
Social Engineering + Malware
Ransomware
Ransomware
Ransomware
Ransomware
Fake Antivirus
Banking Trojans
• Images Overlapping
• GUI Applications
• Pharming
• WebFakes
• HTML Injections
Banking Trojans
• Images Overlapping
• GUI Applications
• Pharming
• WebFakes
• HTML Injections
Banking Trojans
• Images Overlapping
• GUI Applications
• Pharming
• WebFakes
• HTML Injections
GUI Applications
GUI Applications
Banking Trojans
• Images Overlapping
• GUI Applications
• Pharming
• WebFakes
• HTML Injections
Banking Trojans
• Images Overlapping
• GUI Applications
• Pharming
• WebFakes  Phishings
• HTML Injections
Banking Trojans
• Images Overlapping
• GUI Applications
• Pharming
• WebFakes
• HTML Injections
HTML Injections
HTML Injections
HTML Injections VS WebFakes
Injections – How they work (I)
• Trojan
– Binary
• Generic
– Keylogging, form-grabbing, etc.
– Stealing data silently
– Configuration file
• Specific affectation
– Custom attack to entities
– User interaction
Injections - How they work (II)
• Configuration
– Injecting where?
– Injecting what?
– Injecting when?
• Flags: G,P,L
Injections - How they work (III)
1. URI found?
2. Obtain webpage
3. Find starting mark
4. Injection
5. Copy from the ending mark
6. Obtain data thanks to formgrabbing
Injections – How they work (IV)
Authentication
Virtual Keyboard
Code Card
OTP Token
SMS : mTAN
PasswordID +
2FA
Bypassing Authentication
• ID + Password + Operations Password
Bypassing Authentication
• Virtual Keyboard
– Injection is not necessary here
Bypassing Authentication
• 2FA: Code Card
Bypassing Authentication
• 2FA: SMS
– Cheat on the user to infect his mobile phone
• Always after login
• Security Software simulation
• Activation simulation
• Profit from the ignorance of the threat
Bypassing Authentication
• ZeuS + Mobile Component (I)
Bypassing Authentication
• ZeuS + Mobile Component (and II)
Bypassing Authentication
• SpyEye + Mobile Component (I)
Bypassing Authentication
• SpyEye + Mobile Component (and II)
Bypassing Authentication
• 2FA: Token
– MitB Attack  It is NOT Social Engineering
• Mobile Transfer warnings?
– Let’s play “Simon says…”
Demo
Affected countries
Affected Sectors
Underground Market
• Binaries Market
• Injections Market
– Standardized
– Single Injections
– Full-package
Underground Market
• Binaries Market
• Injections Market
– Standardized  ZeuS & co. / SpyEye
– Single Injections
– Full-package
Underground Market
• Binaries Market
• Injections Market
– Standardized
– Single Injections
• Per countries and entities
• 60 WMZ/LR (WebMoney / Liberty Reserve)
• Package: 700-800 WMZ/LR
• Update / Modification: 20 WMZ/LR
– Full-package
Underground Market
Underground Market
• Binaries Market
• Injections Market
– Standardized
– Sólo inyecciones
– Full-package
• Botnet Renting + Injections
• $400??
Underground Market
Underground Market
• How do they create them?
– Obtaining legit code from the banking pages
– Injection creation
– Testing
Underground Market
• How do they create them?
– Obtaining legit code from the banking pages
– Injection creation
– Testing
Underground Market
• Obtaining legit code from the banking pages
– Manual
• Login + Dumping pages
Underground Market
• Obtaining legit code from the banking pages
– Automatic
• Specific modules
• Configuration file
Underground Market
• Obtaining legit code from the banking pages
– Automatic
• Specific modules
– Tatanga
• Configuration file
Underground Market
Underground Market
Underground Market
• Obtaining legit code from the banking pages
– Automatic
• Specific modules
• Configuration files
– ZeuS
– SpyEye
Underground Market
Underground Market
• How do they create them?
– Obtaining legit code from the banking pages
– Injection creation
– Testing
Underground Market
• How do they create them?
– Obtaining legit code from the banking pages
– Injection creation  SOCIAL ENGINEERING!!
– Testing
Underground Market
• How do they create them?
– Obtaining legit code from the banking pages
– Injection creation
– Testing
• Login
• Screenshots
• Video  Tatanga, Citadel
• Detection / Prevention
• Information / Trainings
• Common sense
Solutions??
• Detection / Prevention
– Client
• Check HTML structure (DOM)
– Server
• Additional parameters
• Dynamique pages  Avoid locating injection point
Solutions??
• Detection / Prevention
Solutions??
• Detection / Prevention
• Information / Trainings
• Common sense
Solutions??
• Detection / Prevention
• Information / Trainings
• Common sense
Solutions??
• Detection / Prevention
• Information / Trainings
• Common sense…is not so common
Solutions??
Conclusions
• If the user can make a transfer you will always
be able to cheat on him and change the
destination of the money
• How would you cheat on the user by phone?
Do it after the login, use a fake webpage, or
even call him!
Questions??
¡¡Thanks!!
Mikel Gastesi
@mgastesi
Jose Miguel Esparza
@EternalTodo

Contenu connexe

Similaire à Social Engineering and Banking Trojans: How Criminals Manipulate Users

Leone ct#1 presentation 1
Leone ct#1 presentation 1Leone ct#1 presentation 1
Leone ct#1 presentation 1vincentleone
 
Ethical Hacking & Network Security
Ethical Hacking & Network Security Ethical Hacking & Network Security
Ethical Hacking & Network Security Lokender Yadav
 
Crontab Cyber Security session 4
Crontab Cyber Security session 4Crontab Cyber Security session 4
Crontab Cyber Security session 4gpioa
 
Information security Presentation
Information security Presentation  Information security Presentation
Information security Presentation dhirujapla
 
Social engineering tales
Social engineering tales Social engineering tales
Social engineering tales Ahmed Musaad
 
E security and payment 2013-1
E security  and payment 2013-1E security  and payment 2013-1
E security and payment 2013-1Abdelfatah hegazy
 
Introduction to hackers
Introduction to hackersIntroduction to hackers
Introduction to hackersHarsh Sharma
 
Learn how to protect against and recover from data breaches in Office 365
Learn how to protect against and recover from data breaches in Office 365Learn how to protect against and recover from data breaches in Office 365
Learn how to protect against and recover from data breaches in Office 365AntonioMaio2
 
Hacker risks presentation to ACFE PR Chapter
Hacker risks presentation to ACFE PR ChapterHacker risks presentation to ACFE PR Chapter
Hacker risks presentation to ACFE PR ChapterJose L. Quiñones-Borrero
 
Refugees on Rails Berlin - #2 Tech Talk on Security
Refugees on Rails Berlin - #2 Tech Talk on SecurityRefugees on Rails Berlin - #2 Tech Talk on Security
Refugees on Rails Berlin - #2 Tech Talk on SecurityGianluca Varisco
 
Social engineering
Social engineeringSocial engineering
Social engineeringRobert Hood
 
itsecurityawareness-v1-230413174238-5e7cba3c.pdf
itsecurityawareness-v1-230413174238-5e7cba3c.pdfitsecurityawareness-v1-230413174238-5e7cba3c.pdf
itsecurityawareness-v1-230413174238-5e7cba3c.pdfMansoorAhmed57263
 

Similaire à Social Engineering and Banking Trojans: How Criminals Manipulate Users (20)

Social Engineering
Social EngineeringSocial Engineering
Social Engineering
 
Leone ct#1 presentation 1
Leone ct#1 presentation 1Leone ct#1 presentation 1
Leone ct#1 presentation 1
 
Ethical Hacking & Network Security
Ethical Hacking & Network Security Ethical Hacking & Network Security
Ethical Hacking & Network Security
 
Computer Security
Computer SecurityComputer Security
Computer Security
 
Crontab Cyber Security session 4
Crontab Cyber Security session 4Crontab Cyber Security session 4
Crontab Cyber Security session 4
 
Information security Presentation
Information security Presentation  Information security Presentation
Information security Presentation
 
Red team Engagement
Red team EngagementRed team Engagement
Red team Engagement
 
Social engineering tales
Social engineering tales Social engineering tales
Social engineering tales
 
Cyber security
Cyber securityCyber security
Cyber security
 
Two-Steps to Owning MFA
Two-Steps to Owning MFATwo-Steps to Owning MFA
Two-Steps to Owning MFA
 
E security and payment 2013-1
E security  and payment 2013-1E security  and payment 2013-1
E security and payment 2013-1
 
Introduction to hackers
Introduction to hackersIntroduction to hackers
Introduction to hackers
 
Hacking
HackingHacking
Hacking
 
Learn how to protect against and recover from data breaches in Office 365
Learn how to protect against and recover from data breaches in Office 365Learn how to protect against and recover from data breaches in Office 365
Learn how to protect against and recover from data breaches in Office 365
 
Ethical hacking
Ethical hackingEthical hacking
Ethical hacking
 
Webinar cybersecurity presentation-6-2018 (final)
Webinar cybersecurity presentation-6-2018 (final)Webinar cybersecurity presentation-6-2018 (final)
Webinar cybersecurity presentation-6-2018 (final)
 
Hacker risks presentation to ACFE PR Chapter
Hacker risks presentation to ACFE PR ChapterHacker risks presentation to ACFE PR Chapter
Hacker risks presentation to ACFE PR Chapter
 
Refugees on Rails Berlin - #2 Tech Talk on Security
Refugees on Rails Berlin - #2 Tech Talk on SecurityRefugees on Rails Berlin - #2 Tech Talk on Security
Refugees on Rails Berlin - #2 Tech Talk on Security
 
Social engineering
Social engineeringSocial engineering
Social engineering
 
itsecurityawareness-v1-230413174238-5e7cba3c.pdf
itsecurityawareness-v1-230413174238-5e7cba3c.pdfitsecurityawareness-v1-230413174238-5e7cba3c.pdf
itsecurityawareness-v1-230413174238-5e7cba3c.pdf
 

Dernier

The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfEnterprise Knowledge
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking MenDelhi Call girls
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CVKhem
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘RTylerCroy
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...Neo4j
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking MenDelhi Call girls
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Igalia
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxMalak Abu Hammad
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...apidays
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Drew Madelung
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEarley Information Science
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsEnterprise Knowledge
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Miguel Araújo
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfsudhanshuwaghmare1
 

Dernier (20)

The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptx
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 

Social Engineering and Banking Trojans: How Criminals Manipulate Users