IBM Says Uncovered Sophisticated Bank Transfer Cyber-Scam

Advertisement
By Reuters | Updated: 3 April 2015 10:57 IST
IBM has uncovered a sophisticated fraud scheme run by a well- funded Eastern European gang of cybercriminals that uses a combination of phishing, malware and phone calls that the technology company says has netted more than $1 million from large and medium-sized US companies.

The scheme, which IBM security researchers have dubbed "The Dyre Wolf," is small in comparison with more recent widespread online fraud schemes but represents a new level of sophistication.

According to IBM, since last year the attackers have been targeting people working in companies by sending spam email with unsafe attachments to get a variant of the malware known as Dyre into as many computers as possible.

Advertisement

If installed, the malware waits until it recognizes that the user is navigating to a bank website and instantly creates a fake screen telling the user that the bank's site is having problems and to call a certain number.

If users call that number, they get through to an English-speaking operator who already knows what bank the users think they are contacting. The operator then elicits the users' banking details and immediately starts a large wire transfer to take money out of the relevant account.

Advertisement

The use of a live phone operator is what makes the scheme unique, said Caleb Barlow, vice president of IBM Security.

"What's very different in this case, is we saw a pivot of the attackers to use a set of social engineering techniques that I think are unprecedented," said Barlow. "The focus on wire transfers of large sums of money really got our attention."

Advertisement

IBM did not release any details on which companies fell prey to the scheme or the location of the perpetrators.

Once the transfer is complete, the money is then quickly moved from bank to bank to evade detection. In one instance, IBM said, the gang hit the victim company with a denial of service attack - essentially bringing down their Web capabilities - so it would not discover the theft until much later.

Advertisement

International Business Machines's security unit is recommending that companies make sure employees are trained in spotting phishing attacks - where emails or attachments can infect a computer - and to never provide banking credentials to anyone.

The unit published a blog on the issue on its site.

© Thomson Reuters 2015

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: IBM, Internet, Cyber, Cybercrime, Cybercriminals
Advertisement

Related Stories

Popular Mobile Brands
  1. Apple WWDC 2026 Artwork Teases New Siri Interface, AI Features in iOS 27
  1. OnePlus Nord CE 6 Listed on Geekbench With Snapdragon 7s Gen 4 Chip, 8GB RAM
  2. Apple’s WWDC 2026 Teaser Hints at Siri Overhaul With New UI, AI Features: Report
  3. NASA Observes Rare Sungrazer Comet Disintegration Near the Sun
  4. Kolaiseval Out on OTT: Know Everything About This Tamil Psychological Thriller Film Online
  5. Band Melam OTT Release Date Revealed: Know When and Where to Stream it Online
  6. LEGO Friends: The Next Chapter Season 4 Now Streaming on Netflix: What You Need to Know
  7. Small NASA Satellite Could Reveal How Lightning Impacts Space Weather
  8. Piece by Piece: Pharrell Williams’ LEGO Documentary Now Streaming on Netflix
  9. Ustaad Bhagat Singh OTT Release: When & Where to Watch Pawan Kalyan’s Telugu Film Online
  10. Battleground Season 2 Now on OTT: Know Where to Watch This Ultimate Fitness Reality Show Online
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.