A Pennsylvania organization that helps develop affordable housing learned a painful lesson about the hazards of online banking using the Windows operating system when a notorious trojan siphoned almost $480,000 from its account.Why do you rob banks? That's where the money is. And that's where the malware is going.
News reports here and here say $479,247 vanished from a bank account belonging to the Cumberland County Redevelopment Authority after it was hit by Clampi. The trojan gets installed by tricking users into clicking on a file attached to email and then lies in wait for the victim to log in to online financial websites. The authority has so far been able to recover $109,467 of the stolen loot.Brian Krebs from the Washington Post has been all over this:
It's gotten so bad that Krebs says it's time to throw in the towel: don't ever bank online from a Windows computer:
Imagine being in charge of your organization's finances, and learning from your bank one morning that thieves had stolen tens of thousands of dollars from company coffers overnight using your online banking credentials. Now imagine your frustration when you go to log in to your PC to assess the damage, only to find that the computer you typically use to access the account has been kneecapped by the bad guys.
This is precisely what happened to Kathy Dake, office manager for St. Isidore Catholic Church in Danville, Calif. Dake had infected her PC with the Zeus Trojan after opening a malicious e-mail disguised as notice from the IRS about "unreported income" (see New IRS Scam Could Be Costly).
Folks, as someone who's been in the security industry for 20 years, it's time to admit that we're losing the fight.Windows is simply not securable in any meaningful sense against a motivated attacker. Is it good enough to keep yout pictures and music on? Sure. Games? No sweat. Even company word processing and email - not many Bad Guys care enough to look for specific data to steal, although if you have very high value Intellectual Property, you're not safe. But for most business uses, the pain of the Bad Guys getting on your system has so far been less than the cure.
An investigative series I've been writing about organized cyber crime gangs stealing millions of dollars from small to mid-sized businesses has generated more than a few responses from business owners who were concerned about how best to protect themselves from this type of fraud.
The simplest, most cost-effective answer I know of? Don't use Microsoft Windows when accessing your bank account online.
I do not offer this recommendation lightly (and at the end of this column you'll find a link to another column wherein I explain an easy-to-use alternative). But I have interviewed dozens of victim companies that lost anywhere from $10,000 to $500,000 dollars because of a single malware infection. I have heard stories worthy of a screenplay about the myriad ways cyber crooks are evading nearly every security obstacle the banks put in their way.
But banking is a different thing. It's not like a credit card, where the card issuer will cover most of the fraudulent transactions. If a anking trojan transfers all your money to the Ukraine, you're the one who will have to prove that it wasn't you. In fact, your bank may be prohibited (by law) of covering your loss.
Krebs has a solution, which is to use a Linux "live boot" CD. Basically, this is a Linux image that you download and burn to a CD (or USB flash drive). You can boot from it, and have a complete Linux system - including Firefox - that you can use to do your banking. When you're done, you remove the CD, and reboot into Windows. If you have Malware (and sadly, you probably do), the malware doesn't ever run while you're at your bank, because it doesn't work under Linux.
Krebs describes how to do this, and I encourage you to co read it. It's a great idea, and IMO one of the most important security reads for a general public that I've ever seen. It's a clever idea, and lets you keep the convenience of banking online (if that's your bag, baby). It also entirely eliminates the danger of banking trojans - at least until a lot more people start using Linux, so that market share makes it worth the Bad Guy's time to target Ubuntu.