WEST PALM BEACH, Fla.-Hacking into your credit union's database has never been so cheap and easy, thanks be to Zeus.
Wanna-be fraudsters are just an Internet connection away from downloading free, effective hacking tools from criminal websites and file-sharing programs. The most pernicious free tool on the Net today? Certainly the Zeus Banking Trojan, malicious softwarethatcan download itself onto computers and steal data.
But Zeus has friends. Security experts outlined five do-it-yourself hacking tools that can pack a punch against CUs and members.
THREAT: Zeus Banking Trojan
Problem: Zeus "dominates the financial malware market," according to the Counter Threat Unit at SecureWorks, the Atlanta-based company providing information security services. Zeus is "solely dedicated to doing online financial fraud against customers of financial institutions" and already has netted millions of dollars for fraudsters worldwide, said SecureWorks, which takes credit for discovering Zeus in 2007.
"Zeus is frequently updated and offers criminals many options," agreed John Brozycki, IS officer at $3-billion Hudson Valley FCU in Poughkeepsie, N.Y. "It has built-in capabilities to hide on a PC and bypass most anti-virus and anti-malware products by constantly changing the look of its code without changing the underlying functionality."
Criminals normally use Zeus to steal data from members' computers, not from CU databases, Brozycki added. "As institutions have gotten better at security, end-users have become the easier target."
The deluxe, updated model of Zeus goes for $8,000, but older versions can be downloaded for free, said Brozycki.
Solution: CUs should tell members to restrict their online banking and financial activity to workstations that aren't used for other Internet activity such as Web browsing or e-mail, which increases the vulnerability to Zeus infections, SecureWorks advised. Member businesses may even consider using an alternative operating system for workstations accessing sensitive or financial accounts, said SecureWorks. Anti-virus, anti-malware, operating system and software patches should be current, and end-users should avoid opening suspicious email attachments or links.
THREAT: Metasploit
Problem: Metasploit is free to download at www.metasploit.org and "could pack a wallop against a credit union," said Mark Bell, EVP-operations at San Antonio, Texas-based Digital Defense. "Metasploit brings together dozens of hacking exploits and tools into a single interface that is easy for even novice hackers to use," Bell said. "If a credit union has a known vulnerability, it's almost certain that Metasploit has a module that can exploit it."
Solution: "Implement a robust vulnerability lifecycle management program," Bell suggested. "This program should consist of a recurring cycle of vulnerability identification, remediation and verification of remediation actions to ensure the credit union's network remains secure."
THREAT: ATM Skimmers
Problem: "We specialize in building NCR ATM Skimmers," boasts the website of URSS Electronics, a Russian company that sells skimmers starting at $2,000 via the Internet. "We can usually custom-build skimmers," the company adds. URSS is not alone. "Kits to build or buy hardware that mounts over an ATM's existing card reader slot while looking like a part of the ATM are widely available for a range of ATM models," Brozycki said. "Cameras to observe the PIN entry can be hidden in a fake fascia that overlays the ATM's front without arousing suspicion."
Solution: Anti-skimming sensors and alarms are available. CUs should regularly inspect ATMs for changes and monitor transaction logs for unusual patterns. Members should report ATMs that function strangely or have loose parts.
THREAT: CU Employees
Problem: Employees may be the weakest link in the chain, said Bell. "By using social engineering tactics to entice an internal user to open an infected e-mail attachment or visit a hostile website, a hacker can quickly bypass a credit union's technical defenses and cause grave damage."
Social engineering doesn't require technical savvy or money, added Bill Podborny, director, infrastructure and security for $7-billion Alliant CU in Chicago. "A hacker can call into the call center and try to reset someone's online banking password."
Solution: A recurring security awareness program "to ensure security is always top of mind" for employees, Bell said.
THREAT: Phishing
Problem: By replicating a CU's log-in and verification screens, hackers can set up fraudulent online banking sites. "It's cheap to create and host a phishing site and blast out emails" that lure members, Podborny said.
Solution: Member and employee awareness is the best defense against phishing, as well as a partner that can quickly shut down phishing sites, he said.










