HomeSecurityInternational cooperation against Shylock, which attacks online banking systems

International cooperation against Shylock, which attacks online banking systems

shylok-thumb-large

State and private law enforcement authorities are taking joint action to combat digital crime committed using the Shylock program, which attacks online banking systems.

As announced by the private anti-malware software company Kaspersky Lab, efforts to detect the digital attacks began on July 8.

According to what was reported, the actions included shutting down the servers that constitute the Trojan virus's "Command & Control" system, as well as taking control of the domains that Shylock uses for communication between the computers it has infected.

The operation is being coordinated by the UK's National Crime Agency (NCA).

Law enforcement and private sector organizations are collaborating. In addition to Kaspersky Lab, the operation includes Europol, the FBI, BAE Systems Applied Intelligence, Dell SecureWorks, and the UK's Central Communications Authority, with a common goal of tackling the threat.

Europol's European Cybercrime Centre (EC3), based in The Hague, took over the investigation. Investigators from the United Kingdom (NCA), the United States (FBI), Italy, the Netherlands and Turkey joined forces and coordinated the operation at the local level, in consultation with counterparts in Germany, France and Poland.

Coordination through Europol was instrumental in taking down the servers that were the core of the botnets, malware and Shylock infrastructure. The CERT-EU (EU Computer Emergency Response Team) team participated in the operation and informed its partners about the malicious domains.

During the coordinated action, many aspects of the infrastructure that were previously unknown were revealed. These revelations allowed immediate action to be taken, which was coordinated from the operational center in The Hague.

What is Shylock?

The Shylock malware, so named because its code contains excerpts from Shakespeare's play "The Merchant of Venice," has infected at least 30,000 Microsoft Windows computers worldwide.

According to the research, Shylock targets mainly the United Kingdom. However, systems from the United States, Italy, and Turkey are also targeted by the malicious code. However, there are suspicions that the malware developers are based in another location.

Victims are typically infected when they click on malicious links and are then convinced to unknowingly download and execute the malware. Shylock then seeks to access funds held in corporate or personal bank accounts, in order to transfer them to the criminals who control its operations.

“The European Cybercrime Centre (EC3) is very pleased with the outcome of the operation against this advanced malware, as it played a particularly important role in the effort to combat the criminal infrastructure. EC3 provided a unique platform and operational spaces equipped with state-of-the-art technical infrastructure and secure means of communication, as well as analysts and cyber experts. In this way, we were able to support the digital investigators on the front line, with the coordination of the British NCA and the cooperation with the FBI and colleagues from Italy, Turkey and the Netherlands. At the same time, through virtual links, the investigators were able to cooperate with corresponding units in Germany, France and Poland,” commented Trolls Erting, Head of EC3 at Europol. He added: “I was very pleased to see the international cooperation between law enforcement and prosecutors from many countries. Once again, we were able to test our improved capabilities in responding promptly to cyber threats inside or outside the European Union. This is another step in the right direction for EU law enforcement and prosecutors. I would like to thank everyone involved in the operation for their immense dedication. I would like to thank Kaspersky Lab, which made a significant contribution to the successful outcome of the operation. Our cooperation with the company continues to expand both in this case and in future cases.”.

Andy Archibald, Deputy Director of the Cybercrime Unit at the UK National Crime Agency (NCA), added: “The NCA is taking a leading role in combating a digital threat to businesses and users around the world. This phase of the operation aims to significantly disrupt Shylock’s infrastructure. The operation also highlights how we are using cross-sector and transnational collaboration to tackle digital crime.”.

Moreover, Sergey Golovanov, chief security researcher at Kaspersky Lab, which provided threat intelligence services and monitored malware activity within the global business, said: “Bank fraud campaigns are no longer an isolated phenomenon, as we have observed a significant increase in this type of malicious attacks. In 2013 alone, digital attacks with malware designed to steal financial data increased by 27.6%, reaching 28.4 million. To combat cybercrime, we provide threat intelligence to law enforcement agencies around the world and cooperate with international organizations, such as Europol. Global action and cooperation bring positive results, and the operation against Shylock is another example of this,” Kaspersky’s statement said.

Source: kathimerini.gr

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS