Cybercriminal groups, using a combination of BEC (Business Email Compromise) scams and advanced keyloggers, target, scour and steal data from 18 countries worldwide.
At the heart of this attack is a new malware family with keylogging and info-stealing capabilities, which Trend Micro researchers have dubbed Olympic Vision.
Available on the Dark Web for $25 (€22), this keylogger can do many things, such as log key strokes, record and steal data from the clipboard, capture desktop screenshots and extract passwords from browsers, e-mail and FTP clients.
To spread, criminals have launched specific email campaigns that target key personnel within the target companies.
Also known as BEC scams and sometimes as whaling attacks or CEO fraud, these emails are carefully crafted to look like they are coming from a business associate or other employee of the company.
Each email had an attached file and in this particular campaign, it was the Olympic Vision keylogger, which when executed, would collect data and send it to the intruder.
The criminals would then look through the logs and decide which computer company to attack, based on the data they stole from each, separating the menial jobs from those of the office manager or the company's finance department.
The targeted countries are equally distributed worldwide. Attackers strike in China, India, Indonesia, Malaysia, Thailand, Canada, the United States, Germany, Iran, Iraq, the Netherlands, Qatar, Saudi Arabia, Slovakia, Spain, the United Arab Emirates, the United Kingdom and Zimbabwe.
This is not the first time that keyloggers have been used in conjunction with BEC scams, Trend Micro stated in a past report on other threats, such as Predator Pain, Limitless, and Hawkeye.
According to Mimecast, a cybersecurity security vendor specializing in the field of email security, BEC scams increased by 55% in 2015 compared to the previous year.


