IBM discovers ‘Dyre’ bank transfer fraud scam

IBM discovers ‘Dyre’ bank transfer fraud scam

The fraud scheme has stolen roughly $1 million from U.S. bank accounts.

IBM has uncovered an ultra-sophisticated cyber fraud scam that makes use of malware, DDoS attacks, spear phishing, and even good old fashioned social engineering. According to a report in Reuters, IBM believes that a European cyber criminal gang is behind the scheme, which targets enterprise bank accounts and has stolen over $1 million from large and medium sized companies in the United States.

Security researchers at IBM have dubbed this criminal campaign the “Dyre Wolf,” due to its use of a strain of the Dyre malware, along with a strategy of deception reminiscent of the “Wolf of Wall Street.”

“What do the dire wolf, the wolf in sheep’s clothing and ‘The Wolf of Wall Street’ have in common? Deception and a ferocious appetite to get what they want,” IBM senior threat researcher John Kuhn wrote in a blog post. “The Dyre Wolf campaign is no different.”

The scam starts off with the attackers sending out spam email with unsafe attachments designed to inject the Dyre malware into as many computers as possible, Reuters reports. Once the malware is on a computer, it lies in wait until a user visits a bank website, and then instantly generates a fake web page informing the user that the bank’s site is having problems. The fake page instructs the user to call a certain number.

If users call that number, the real deviousness of the scam kicks in. The unknowing victim will actually reach an English-speaking operator who knows which bank they should be impersonating. While impersonating a representative of that bank, the operator will persuade the victim to give up bank account details, which are then used to begin a large wire transfer removing money from the account.

“What’s very different in this case, is we saw a pivot of the attackers to use a set of social engineering techniques that I think are unprecedented,” Caleb Barlow, IBM Security VP, told Reuters. “The focus on wire transfers of large sums of money really got our attention.”

Be social, please share!

Facebooktwittergoogle_plusredditpinterestlinkedintumblrmail