Phishing
The Universal Man-in-the-Middle Phishing Kit uses a simple and user-friendly online interface to create fraudulent URLs

IT security experts warn of phishing kit peril

Universal Man-in-the-Middle phishing kit discovered by RSA

Written by Robert Jaques

Security experts have warned that a previously undocumented phishing kit is being sold and used online by fraudsters.

The newly uncovered Universal Man-in-the-Middle Phishing Kit is designed to allow cyber-criminals to create sophisticated attacks against global organisations in which the victims communicate with a legitimate website via a fraudulent URL.

Security firm RSA's Anti-Fraud Command Center warned that this allows the fraudster to capture victims' personal information in real time.

RSA's experts reported that they had analysed a demo of the kit that was being offered as a free trial on an online forum known to be frequented by fraudsters.

Using the Universal Man-in-the-Middle Phishing Kit, the scammer creates a fraudulent URL via a simple and user-friendly online interface.

This URL communicates in real time with the legitimate website of the targeted organisation, whether it is the online banking site of a financial institution, the order tunnel of an e-commerce company, or any other such business transacting with its users online.

The victim then receives a 'standard' phishing email with a link to the fraudulent URL and interacts with genuine content from the legitimate website which has been "imported" by the attack into the phishing URL.

This affords the fraudster seamless and immediate access to the victim's personal information.

Marc Gaffan, director of marketing for consumer solutions at RSA, said: "As institutions put additional online security measures in place, the fraudsters are looking at new ways of duping innocent victims and stealing information and assets.

"While these types of attacks are still considered 'next generation', we expect them to become more widespread over the course of the next 12 to 18 months."

See also:

reader comments

related articles

 

Infosec: Rock Phish threat deepens

Hugely successful malware gets a new twist 23 Apr 2008

Fraud-as-a-service looms over firms

Criminals are offering fraud services via chat rooms and forums 28 Oct 2008

Experts sound alarm on Silentbanker Trojan

More than 400 banks on malware hitlist 15 Jan 2008

latest news

Ballmer highlights aims for New Year

Ballmer announces Windows 7 beta and future alliances designed to improve information sharing 08 Jan 2009

Active Storage completes UK Jigsaw

Jigsaw unveiled as Raid vendor's first non-US Platinum partner as it launches in Europe 08 Jan 2009

Dell quits Irish production

Vendor to slash 1,900 jobs in Limerick as it migrates assembly for EMEA customers to Poland 08 Jan 2009

poll

Challenging times ahead?

Challenging times ahead?

Do you think there will be a lot of channel job cuts in 2009?

Previous poll results

Paul Anderson, Trend Micro

Vendor Q&A: Paul Anderson, Trend Micro

During this Q&A session Paul Anderson, UK country manager of Trend Micro talks about the changing threat landscape and how Trend is working with resellers in 2009

Sara Yirrell and Rick Wallis

Vendor Q&A: Rick Wallis, NEC Computers

In this exclusive vendor Q&A, Rick Wallis, UK sales director at NEC Computers talks to CRN editor Sara Yirrell about his firm’s plans for the channel.

events

Channel Expo 2009 logo

Channel Expo 2009

The UK's top reseller exhibition will return to the NEC on 20 May 2009

CRN Fight Night 2009

The channel's only white-collar boxing event is back

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

White papers

Search white papers

Top categories

Primary Navigation