Share

Related Links

Related Stories

  • The Gods of Phishing
    Some phishing attempts are truly ethereal – near flawless representations of official communications. Others, however, are mere mortals. And then there’s the absolutely absurd. Esther Shein visits the pantheon of scammer emails
  • Beware of bogus online offers bearing a free iPad
    Bogus offers for free iPads pose one of the most pernicious threats to online shoppers this holiday season, noted Sam Masiello, director of threat management at McAfee.
  • Porn sites top drive-by download list
    Porn sites are still the most likely online destinations to be compromised with malware, in spite of increasing attacks on legitimate non-porn websites, according to a report released by security company Commtouch this week.
  • Zero Day of the Dead
    The data load that has accompanied the globalization of trade would make even Atlas stagger. And that’s without the added burden of counter-terrorisAs you read this, zombie programs are flitting across the internet like a pestilence to infect and drain the life from innocent computer systems. Yet, for all the aggravation and grief they cause, you may never know you are part of a global invasion of the system snatchers, says William Knight. Unless…
  • Scammers use Google Docs survey form to dupe ANZ Bank customers
    SophosLabs has recently discovered a phishing scam targeting ANZ Bank customers using a Google Docs survey form.

Top 5 Stories

News

Aussie bank customers hit by advanced phishing techniques

03 June 2009

Customers of the Commonwealth Bank in Australia are being targeted by a new breed of phishers, who seem intent on scamming them out of their e-banking and payment card details.

Reports from Australia suggest that some of the phishers are using highly advanced scamming techniques to extract the data - including asking email recipients to phone into an automated 'call centre' and
so allay the fears of even the most tech-savvy of internet users.

The phishers also appear to have rediscovered the art of using images, rather than text, to bypass anti-phishing/spamming software.

Interestingly, Infosecurity notes that some of the phishers are reportedly using a pixel-shifting technique to ensure that different emails have different images, so avoiding pattern analysis security software.

The Commonwealth Bank says it is working with the Australian Federal Police's High Tech Crime Centre to track down the phishers, although the scammers appear to be using anonymiser services to hide their IP trails.

The surge in phishing attacks also appears to have been going on for some time in Australia, with the Australian Payments Clearing Association reporting a 33% increase in phishing volumes in 2008 compared to 2007.

What is interesting about the phishing emails is that, as well as rotating images and email addresses, the scammers are using different text within the image to escape detection.

The text asks recipients to contact an automated call centre in order to unlock an account, activate a card, claim a fee refund, update internet banking details, view an important security message or complete a survey in exchange for payment.

The final step in the rotational process is the use of multiple landing pages with users clicking on the links in the mail and being taken to pages that either infect them (with different viruses) or a landing page requesting details of their account(s).

Judging from reports on several Australian security forums, the phishing techniques used by the scammers are highly sophisticated and represent a seachange in the way phishers operate, Infosecurity notes.

This article is featured in:
Data Loss  • Internet and Network Security • Malware and Hardware Security

 

Comment on this article

You must be registered and logged in to leave a comment about this article.