Newsletter:

Skip Navigation LinksHome > News > Security > IT security experts warn of phishing kit peril

IT security experts warn of phishing kit peril

By Robert Jaques
12 January 2007 02:28PM
Tags: security | phishing

Universal Man-in-the-Middle phishing kit discovered by RSA.

Security experts have warned that a previously undocumented phishing kit is being sold and used online by fraudsters.

The newly uncovered Universal Man-in-the-Middle Phishing Kit is designed to allow cyber-criminals to create sophisticated attacks against global organisations in which the victims communicate with a legitimate website via a fraudulent URL.

Security firm RSA's Anti-Fraud Command Center warned that this allows the fraudster to capture victims' personal information in real time.

RSA's experts reported that they had analysed a demo of the kit that was being offered as a free trial on an online forum known to be frequented by fraudsters.

Using the Universal Man-in-the-Middle Phishing Kit, the scammer creates a fraudulent URL via a simple and user-friendly online interface.

This URL communicates in real time with the legitimate website of the targeted organisation, whether it is the online banking site of a financial institution, the order tunnel of an e-commerce company, or any other such business transacting with its users online.

The victim then receives a 'standard' phishing email with a link to the fraudulent URL and interacts with genuine content from the legitimate website which has been "imported" by the attack into the phishing URL.

This affords the fraudster seamless and immediate access to the victim's personal information.

Marc Gaffan, director of marketing for consumer solutions at RSA, said: "As institutions put additional online security measures in place, the fraudsters are looking at new ways of duping innocent victims and stealing information and assets.

"While these types of attacks are still considered 'next generation', we expect them to become more widespread over the course of the next 12 to 18 months."

Copyright © 2008 vnunet.com

   


Ads by Google


Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 


Tripwire - Click here to win an iTouch





Product Reviews

Star Rating
The AdventNet Manage-Engine Password Manager Pro provides a complete system for password management in one...
Star Rating
The Cyber-Ark Enterprise Password Vault, or EPV, is a high-end password management powerhouse.
Star Rating
The Hitachi ID-Archive sets its focus on password randomisation.
Star Rating
The Lieberman Software Enterprise Random Pass­word Manager is a full-on password manager and randomiser for...
Star Rating
Proginet SecurForce is a little bit of a horse of a different color for this month's Group Test.
Unified Communications Podcast Centre

TopTopics
(6631) -  internet
(6415) -  iinet
(6390) -  copyright
(6390) -  afact
(5990) -  servers
(5990) -  mipi
(4796) -  telstra
(4491) -  broadband
(4432) -  nbn
(2926) -  internode
(2464) -  microsoft
(1884) -  network
(1468) -  data
(1382) -  software
(1365) -  google