Thursday, July 24, 2014

Silver Spaniel Loose - New Avatar of the 419 Scam

A trademark of the original Nigerian 419 scams was the badly written email. The email usually appeared to come from some widow who was ready to pay a staggeringly obscene amount of money to get her dead husband's money out of the country. All that she needed was some help from someone willing to put in some initial investment to get things moving. 

Once the victim paid, the fraudsters took the money and disappeared.

The original simple fraudsters have now graduated to more advanced malware based attacks which have now been dubbed "Silver Spaniel" attacks. These attacks use Remote Administration Tools (RATs) like NetWire and DarkComet which allow the fraudsters to remotely take over control of the target machines.

Anti-virus protection on the victim's side is not entirely effective as the attackers use tools like DataScrambler to repackage the RATs and avoid detection by anti-viruses. 

Using these more effective tools, which are fairly easily available on underground avenues, these attackers have now moved from targetting clueless individuals to medium sized businesses also.