iTnews
  • Home
  • News
  • Technology
  • Security

Infosec: Rock Phish threat deepens

By Iain Thomson
Apr 24 2008 1:48PM
Follow google news

Security firm RSA has warned that the software kit behind half of the world's phishing attacks has been upgraded..


The Rock Phish software has been used in attacks on over 40 European and US financial institutions.

The tool has been very successful, using innovations including unique URL generation to defeat blacklists. But Rock Phish has not used malware as part of its attack until recently.

The fake phishing pages now include a Trojan dubbed Zeus, so that once a victim's financial data has been harvested the Trojan allows the computer to be controlled remotely.

"The victim is duped into visiting a phishing site," said Uriel Maimon from the RSA 24x7 Anti-Fraud Command Center.

"Whether or not the victim surrenders his/her credentials into the site is irrelevant, as many people click on phishing links but do not fill in meaningful information.

"However, with this new attack twist the victim will still be infected with a Trojan."

The group behind the Rock Phish attacks did not develop the Trojan themselves, but purchased it for the job in much the same way as a legal software developer.

Zeus is a very flexible and persistent Trojan which can be used to steal data, make the infected machine part of a botnet and even take regular screenshots of a user's activity.

"The Zeus Trojan has many startling capabilities," said Maimon. "As I look on this blissful union of fraud and crime technologies, I can only envy the criminals who can find such coupling."

The Rock Phish software has become something of a cause célèbre in the IT security industry since it surfaced.

The creators have been described as the Kaiser Söze of the online world, and no-one is sure whether the creator is a single person or a hacking group.

RSA is confident that it is a hacking group behind the code, and no-one disputes that the software has been astonishingly successful.

Hundreds of millions of pounds have been siphoned out of users' bank accounts over the past four years.

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
Copyright ©v3.co.uk
Tags:
infosecphishrocksecuritythreat

Related Articles

  • Anthropic pulls Mythos-class models globally Anthropic pulls Mythos-class models globally
  • AudiA6 crypto launderers arrested, network taken down by police AudiA6 crypto launderers arrested, network taken down by police
  • US charges suspected Russian hacker with facilitating cyber campaign US charges suspected Russian hacker with facilitating cyber campaign
  • Gov looks for upstream threat blocking by telcos, cloud operators Gov looks for upstream threat blocking by telcos, cloud operators
Join our WhatsApp Channel

Partner Content

Take control of your connectivity with Telstra’s Adaptive Networks Centre
Partner Content Take control of your connectivity with Telstra’s Adaptive Networks Centre
The hidden economics of AI: Why token usage matters more than you think
Partner Content The hidden economics of AI: Why token usage matters more than you think
Scalable AI solutions: secure delivery
Scalable AI solutions: secure delivery
Why resilient communications are becoming critical infrastructure for modern enterprise IT
Promoted Content Why resilient communications are becoming critical infrastructure for modern enterprise IT

Sponsored Whitepapers

Are Australian organisations as cyber-ready as they think?
Are Australian organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
From visibility to execution:  Fixing the SaaS management gap
From visibility to execution: Fixing the SaaS management gap
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • Forrester's AI Forum Sydney Forrester's AI Forum Sydney
  • The 2026 iAwards The 2026 iAwards
  • Security Exhibition & Conference Security Exhibition & Conference
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Anthropic releases Mythos-class model for public use

Anthropic releases Mythos-class model for public use

Apple bumps up security in fresh operating system releases

Apple bumps up security in fresh operating system releases

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.