Stack of Money

GCMAN: how to earn 200 dollars a minute

GCMAN: At the Security Summit Analyst Summit (SAS 2016) held in Tenerife, Spain, Kaspersky researchers uncovered a new cybercriminal group.

GCMAN

The group is called GCMAN and targets Russian Banks.

The nickname came from the GCC (GNU Compiler Collection), the compiler used by the team to create the custom-made their.

The distribution of the malicious γινόταν μέσω spear-phishing e-mail που αποστέλλονται σε άτομα- through the organization chart of the bank.

If these people open the malicious RAR file that is attached to the e-mail, their computer is infected with the group's malware.

This malware is designed specifically for moving within the bank's IT infrastructure. He is actively looking for financial transaction servers using penetration testing tools such as Meterpreter, Putty, and VNC to gain access to the systems.

Μόλις ανακαλύψει μηχανήματα που κάνουν συναλλαγές, το κακόβουλο λογισμικό χρησιμοποιεί ένα απλό cron script που αρχίζει να στέλνει 200 δολάρια το λεπτό σε διάφορους λογαριασμούς ψηφιακών νομισμάτων, τους οποίους ν βέβαια οι προγραμματιστές του malware.

The cron script of GCMAN was discovered in error

Kaspersky reports the script was accidentally discovered by a bank employee who encountered GCMAN malware and managed to stop it before executing a transaction.

Immediately thereafter, Kaspersky researchers discovered that the entire computer network of the bank that executed transactions contained malicious software. The infection was carried out 18 months ago on a computer.

The hackers used the machine to attack 70 other computers on the bank's network, and violate 56 until they accessed what they were looking for. Eighteen months later, they returned to place the cron script on the server and begin withdrawals. But it seems that luck was not on their side.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).