what is lurking in the shadows

28
WHAT IS LURKING IN THE SHADOWS ... Eran Kalige Head of Security Operation Center [email protected]

Upload: walden

Post on 11-Jan-2016

38 views

Category:

Documents


1 download

DESCRIPTION

What is Lurking in the shadows. Eran Kalige Head of Security Operation Center [email protected]. Who am I?. Head of security Operation Center At Versafe Years of research and Development. Security expert Security and anti Fraud consultant Famous publications: - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: What is Lurking in the shadows

WHAT IS LURKING IN THE SHADOWS...

Eran KaligeHead of Security Operation [email protected]

Page 2: What is Lurking in the shadows

Head of security Operation Center At Versafe Years of research and Development.

Security expert

Security and anti Fraud consultant

Famous publications:

- Eurograbber banking Trojan

HighRoller Trojan reports

Who am I?

Page 3: What is Lurking in the shadows

Dark side of the net Cyber Crime

Phishing attacks – who where and what it looks like.

Trojan attacks

- How are they distributed?

- Banking Trojans - who are they ? What do they do ? How they do it?

- Automatic transfers & fake balances

- Inside look inside The hackers dropzones

Summary

Agenda

Page 4: What is Lurking in the shadows

Facts and Details

Any victims here?

Page 5: What is Lurking in the shadows

Cyber Criminals

Page 6: What is Lurking in the shadows

The Risk

Page 7: What is Lurking in the shadows

Phishing – Easy & common

Page 8: What is Lurking in the shadows

Phishing – Easy & common

Page 9: What is Lurking in the shadows

Phishing – Protection

Users Avoid clicking on links – go directly to the website.

Verify the HTTPS connection (SSL)

Look for fishy details

Corporate Implement an Anti-phishing solution

Update your Systems – Firewall , anti-spam , Anti-virus etc.

Look for fishy details

Page 10: What is Lurking in the shadows

Trojans

Page 11: What is Lurking in the shadows

Trojans – past players

NetBus or Netbus is a software program for remotely controlling a Microsoft Windows computer system over a network. It was created in 1998 and has been very controversial for its potential of being used as a backdoor.NetBus was written in Delphi by Carl-Fredrik Neikter, a Swedish programmer in March 1998. The author claimed that the program was meant to be used for pranks, not for illegally breaking into computer systems. Translated from Swedish, the name means "NetPrank".

.

Page 12: What is Lurking in the shadows

Trojans today

Host control – VertexNet, Andromeda , Pony , Umbra and more.

Banking Trojans – Zeus , Citadel , Gozi and more

Bitcoin mining Trojans

Espionage and country related – Stuxnet , Magdi and more.

Mobile Trojans – Perkele, OmegaSPY , Zitmo/Eurograbber.

Page 13: What is Lurking in the shadows

Trojans today – Host Control

Page 14: What is Lurking in the shadows

Trojans today – Banking Trojans

Page 15: What is Lurking in the shadows

Trojans today - How they look

Page 16: What is Lurking in the shadows

Trojans today - How they look

DEMO

Page 17: What is Lurking in the shadows

Trojans today – Script injections

Trojan Code Injection

Page 18: What is Lurking in the shadows

Trojans today - Automatic transfers & fake balances

Page 19: What is Lurking in the shadows

ATS – attacker's View

Page 20: What is Lurking in the shadows

Trojans today -Citadel

file:///C:/Users/Eran/Desktop/lecture/vids/videos_voscomptesenligne_labanquepostale_fr_13_05_23__07-16_.webm

Page 21: What is Lurking in the shadows

ATS – OTP bypass

Page 22: What is Lurking in the shadows

Mobile Malware

Page 23: What is Lurking in the shadows

Mobile Malware

Page 24: What is Lurking in the shadows

Trojans today - distribution

• Web sites infected with exploits.

• P2P share – Emule, Torrent, ...

• Worms in social networks, chat rooms, forums, …

• Emails

Page 25: What is Lurking in the shadows

"“I'm scared.. What to do???

Users Avoid clicking on links from people you don’t know.

Install an antivirus software and make sure to – UPDATE!

Scan USBs and other resources you connect to the computer.

Don’t fall for “ watch this video!”

Page 26: What is Lurking in the shadows

Final words...

baby it's a wild world, it's hard to get by just upon a smile...

Page 27: What is Lurking in the shadows

Versafe protects you from Trojans on the End User

QUESTIONS

?

Page 28: What is Lurking in the shadows

Questions...

Eran Kalige

Head of security operation centerVersafe