Follow Slashdot blog updates by subscribing to our blog RSS feed

 



Forgot your password?
typodupeerror
×
Security The Almighty Buck

Tigger.A Trojan Quietly Steals Stock Traders' Data 212

**$tarDu$t** recommends a Washington Post Security Fix blog post dissecting the Tigger.A trojan, which has been keeping a low profile while exploiting the MS08-66 vulnerability to steal data quietly from online stock brokerages and their customers. An estimated quarter million victims have been infected. The trojan uses a key code to extract its rootkit on host systems that is almost identical to the key used by the Srizbi botnet. The rootkit loads even in Safe Mode. "Among the unusually short list of institutions specifically targeted by Tigger are E-Trade, ING Direct ShareBuilder, Vanguard, Options XPress, TD Ameritrade, and Scottrade. ... Tigger removes a long list of other malicious software titles, including the malware most commonly associated with Antivirus 2009 and other rogue security software titles ... this is most likely done because the in-your-face 'hey, your-computer-is-infected-go-buy-our-software!' type alerts generated by such programs just might ... lead to all invaders getting booted from the host PC."
This discussion has been archived. No new comments can be posted.

Tigger.A Trojan Quietly Steals Stock Traders' Data

Comments Filter:
  • by PCM2 ( 4486 ) on Tuesday March 03, 2009 @05:50PM (#27056881) Homepage

    Of course not. You should wait until they're at their 10-year peak and then buy them.

  • time for 2-factor (Score:4, Insightful)

    by Lord Ender ( 156273 ) on Tuesday March 03, 2009 @05:55PM (#27056989) Homepage

    It is time for online financial institutions (brokerages and banks) to require real 2-factor authentication to log in to their sites. When I sign up for a bank account, I want them to mail me an ATM card with an embedded smartcard chip, along with a cheap USB smartcard reader. Alternatively, send a one-time-passphrase device like SecurID.

    This may be a little expensive up front, but it would cut down on enough fraud that it might pay for itself.

  • by amclay ( 1356377 ) on Tuesday March 03, 2009 @05:58PM (#27057013) Homepage Journal
    Probably not. Tigger removes adware/spyware, and not all spyware even then. Viruses are different than your typical spyware. There's a whole host of things that are different than spyware that I'm not going to clarify, but don't go around thinking Tigger is some sort of anti-virus because it's not.
  • by Darkness404 ( 1287218 ) on Tuesday March 03, 2009 @06:00PM (#27057035)

    I want them to mail me an ATM card with an embedded smartcard chip, along with a cheap USB smartcard reader.

    Thats just fine, but they most likely won't release drivers for it for anything other than Windows and perhaps OS X, so any BSD, Linux, or other alternate OS user gets left out.

    Secondly, it would be trivial for an attacker to put in compromised drivers in the system that reads out all the secure info and forwards it to his website where he can duplicate all the secure keys and such.

  • by zach297 ( 1426339 ) on Tuesday March 03, 2009 @06:22PM (#27057327)
    You can't tell something is peaking until after it goes down.
  • by greymond ( 539980 ) on Tuesday March 03, 2009 @06:22PM (#27057329) Homepage Journal

    Someone likes their CSI

  • by NeutronCowboy ( 896098 ) on Tuesday March 03, 2009 @06:28PM (#27057419)

    Err, no. You might have the most likely demographic right, but that's just because they contain the majority of crackers. As for the debt, it is very unlikely someone in that demographic managed to accumulate a lot of debt.

    What I'm pretty sure you got completely wrong is the acting alone part. You do not profit of this kind of targeted scheme by working alone. You either have a taskmaster who requested this info, or you know the people who will be able to profit from this info.

    Really, nice try, but I'm pretty sure you have no idea who the crackers really are, and how they operate. I don't know em personally either, but I've got enough experience with DSM and psychological profiling to call shenanigans on your assessment.

  • by commodoresloat ( 172735 ) on Tuesday March 03, 2009 @06:33PM (#27057495)

    Link it with possible terrorism to bypass the usual rules that would prevent a dragnet, and chances are good you find your man. At least, that's how I'd investigate.

    Well then thank goodness you're not investigating. Crap like this is the exact reason many of us were outraged at the Patriot Act and similar legislation; back in 2001-2 we argued that such legislation would become an easy way for investigators to ignore the Constitution for a host of other crimes. There's been plenty of evidence of that happening already, but it's rare to see someone openly advocate such an abuse of law -- usually, in fact, conservatives defended these laws by saying they would never be used against anyone but the most dangerous international terrorists.

  • Re:Hmm... (Score:4, Insightful)

    by SmurfButcher Bob ( 313810 ) on Tuesday March 03, 2009 @06:37PM (#27057543) Journal

    It's only illegal if your name isn't SONY or BMG. If your name IS SONY or BMG, you simply need to deposit two iTunes songs on the machine, and you're held harmless.

  • by cbiltcliffe ( 186293 ) on Tuesday March 03, 2009 @06:40PM (#27057585) Homepage Journal

    Woooooooosh.

  • Re:Oblig... (Score:5, Insightful)

    by cbiltcliffe ( 186293 ) on Tuesday March 03, 2009 @06:41PM (#27057599) Homepage Journal

    The wonderful thing about tiggers
    Is tiggers are wonderful things!
    Their tops are made out of rubber
    Their bottoms are made out of springs!
    They're bouncy, trouncy, flouncy, pouncy
    Fun, fun, fun, fun, fun!
    But the most wonderful thing about tiggers is.....
    I'm the only one

  • by DigitalCrackPipe ( 626884 ) on Tuesday March 03, 2009 @06:46PM (#27057653)
    I wonder how long it will be until a particular program updates a virus definition list or something similar to remove all other competing malware programs as they come into existence
    Such a malware product exists... it's called McAfee, and while it's not very good it does convince lots of people to pay money for it.
  • by Dutchmaan ( 442553 ) on Tuesday March 03, 2009 @07:00PM (#27057813) Homepage

    -OR-

    Investors, having heard that Obama has the successful in his cross hairs and intends to seize the fruits of their labor and give it to the unsuccessful in the name of fairness, are panicking.

    Don't you mean the fruits of other people's labor. Last time I checked investors don't actually produce anything.

  • by isBandGeek() ( 1369017 ) on Tuesday March 03, 2009 @09:46PM (#27059487)
    Or rather, short sell them.
  • by Overzeetop ( 214511 ) on Tuesday March 03, 2009 @10:11PM (#27059693) Journal

    Microsoft isn't exactly the most trustworthy when it comes to automatically installing anything they want on your computer, which is what you suggest. There doesn't seem to be a checkbox for "only fix security flaws" in Windows Update. I find I still have to sift through the options manually.

  • by tsm_sf ( 545316 ) on Tuesday March 03, 2009 @11:55PM (#27060517) Journal

    Yes yes, we've always known that it's harder to be good than evil. We've got thousand year old texts on the subject, we have pop sci-fi trilogies (ahem) on the subject. It's a known deal.

    Me personally, I'd rather see a few thousands die than see our country go down the path of least resistance. I've been unfortunate enough to see both occur during the past decade.

  • by NeutronCowboy ( 896098 ) on Wednesday March 04, 2009 @01:30AM (#27061105)

    The truth is something that only people of a certain moral flexibility are good at uncovering.

    Err, again, no. The truth has little to do with moral flexibility and all to do with facts. The fact that you confuse the two makes me question whether you understand what truth actually is.

    Finally, you're also sadly mistaken if you assume that what you do on a forum has no repercussions elsewhere. At the very least, what you say on it is a reflection of who you are, and how you will act outside of it. It's not a political act, it's a social statement.

    You might be technically savvy, but your understanding of the rest of the world is seriously lacking. Your confidence in your knowledge will make it difficult for you to learn.

  • Use the farce (Score:1, Insightful)

    by Anonymous Coward on Wednesday March 04, 2009 @10:29AM (#27064015)

    Your lack of experience disturbs me.

    4 years of programming? I think many of us reached 4 years before the age of 10.

    "Caught 2 people on site who attempted to access information without authorization..." gee that means you firm didn't do a good job after the first person.

    Classified, schmlassified. One could work with DEA or NSA, SAIC or LANL, and still be doing classified work. Let's be honest: that doesn't mean it's important. Everybody and his brother has had a TS/SI clearance, bucko. Don't embarrass the real professionals who don't go around trying to impress people on Slashdot.

    AC

Thus spake the master programmer: "After three days without programming, life becomes meaningless." -- Geoffrey James, "The Tao of Programming"

Working...