Phishing: A Direct Deposit to the Criminal World (236905935)

34
Direct Deposit Phishing Attack Brian Allen [email protected] Network Security Analyst Washington University in Saint Louis May 2014

description

In the fall of 2013, Washington University in St. Louis was hit with a phishing attack targeted primarily at medical faculty. The criminals used the compromised credentials to change direct deposit bank account information to steal money. The university quickly made changes to defend against this threat and rethought the current incident response capabilities to better handle widespread attacks. In this presentation, we will walk through the incident to see how and why it was so successful and will discuss steps to detect and prevent these types of incidents. OUTCOMES: Understand how this criminal campaign worked from beginning to end * Learn what defenses can be put into place to disrupt the various phases of this type of attack * Be able to better defend against phishing attacks http://new.educause.edu/events/security-professionals-conference/2014/phishing-direct-deposit-criminal-world

Transcript of Phishing: A Direct Deposit to the Criminal World (236905935)

Page 1: Phishing: A Direct Deposit to the Criminal World (236905935)

Direct Deposit Phishing Attack

Brian [email protected]

Network Security AnalystWashington University in Saint Louis

May 2014

Page 2: Phishing: A Direct Deposit to the Criminal World (236905935)

Topics for Today

• Brief overview of the Washington University network

• Brief look at first incident in Sept/Oct 2013• Brief look at second incident in Jan/Feb 2014• Potential phishing defenses• Some examples of real phishing emails• Who attacked us?• Final thoughts

Page 3: Phishing: A Direct Deposit to the Criminal World (236905935)

Washington University in St. Louis

NSS

NSO

Business School

Law School

Arts & Sciences

Medical School

Engineering School

Internet

Decentralized Campus NetworkNSS = Network Services and SupportNSO = Network Security Office

Library

Social Work

Art & Architecture

Page 4: Phishing: A Direct Deposit to the Criminal World (236905935)

Numbers from Sept/Oct 2013 Attack:

• 13 total victims• 11 Medical School faculty• 2 Business School faculty• 11 had direct deposit info changed• 1 account caught by the new HRMS blacklist

and immediately blocked

Page 5: Phishing: A Direct Deposit to the Criminal World (236905935)

Round 1a Phishing Attack

Page 6: Phishing: A Direct Deposit to the Criminal World (236905935)

Round 1b Phishing Email

Page 7: Phishing: A Direct Deposit to the Criminal World (236905935)
Page 8: Phishing: A Direct Deposit to the Criminal World (236905935)

Numbers From Jan/Feb 2014 Attack

• 17 Users were victims– 15 Medical Faculty or Staff– 1 Engineering School Faculty– 1 Law Student

• 4 Victims had their Direct Deposit info changed• 7 Users were protected by the Blacklist• 10 Victims were logged into from new IP

addresses which were quickly added to the Blacklist

Page 9: Phishing: A Direct Deposit to the Criminal World (236905935)

Round 2 Phish Three Months Later

Page 10: Phishing: A Direct Deposit to the Criminal World (236905935)
Page 11: Phishing: A Direct Deposit to the Criminal World (236905935)
Page 12: Phishing: A Direct Deposit to the Criminal World (236905935)

Criminals seemingly have a huge advantage

They send hundreds of phishing emails and only need ONE user to fall

for it to succeed

Page 13: Phishing: A Direct Deposit to the Criminal World (236905935)

We can turn the tables on them

Force the criminal to run througha gauntlet of defenses to succeed

Page 14: Phishing: A Direct Deposit to the Criminal World (236905935)

Reconnaissance Phase

Page 15: Phishing: A Direct Deposit to the Criminal World (236905935)

Phishing Email Phase

Page 16: Phishing: A Direct Deposit to the Criminal World (236905935)

Criminal Login Phase

Page 17: Phishing: A Direct Deposit to the Criminal World (236905935)

HR/SSO Application Suggestions

Page 18: Phishing: A Direct Deposit to the Criminal World (236905935)

Payroll Alerting Suggestions

Page 19: Phishing: A Direct Deposit to the Criminal World (236905935)

Communication Suggestions

Page 20: Phishing: A Direct Deposit to the Criminal World (236905935)

Phishing Examples

Page 21: Phishing: A Direct Deposit to the Criminal World (236905935)

WUSTL Site or Phish Site?

Page 22: Phishing: A Direct Deposit to the Criminal World (236905935)
Page 23: Phishing: A Direct Deposit to the Criminal World (236905935)

WUSTL Site or Phish Site?

Page 24: Phishing: A Direct Deposit to the Criminal World (236905935)
Page 25: Phishing: A Direct Deposit to the Criminal World (236905935)

WUSTL Site or Phish Site?

Page 26: Phishing: A Direct Deposit to the Criminal World (236905935)

Real Email or Phish Email?

Page 27: Phishing: A Direct Deposit to the Criminal World (236905935)
Page 28: Phishing: A Direct Deposit to the Criminal World (236905935)

Spammers log in and useaccount to send spam

Page 29: Phishing: A Direct Deposit to the Criminal World (236905935)

Sept/Oct Attack 1

Page 30: Phishing: A Direct Deposit to the Criminal World (236905935)

Jan/Feb Attack

Page 31: Phishing: A Direct Deposit to the Criminal World (236905935)

Numbers from September/October:

• 13 total victims• 11 Medical School faculty• 2 Business School faculty• 11 had direct deposit info changed• 1 account caught by the new HRMS blacklist

and immediately blocked

Page 32: Phishing: A Direct Deposit to the Criminal World (236905935)

How Much $ Did the Criminals Get in October?

• $97,210.28 Total was Transferred Out• $91,470.53 Was Recovered by Payroll• $5,739.75 Was Lost

.

$0.00

$20,000.00

$40,000.00

$60,000.00

$80,000.00

$100,000.00

$120,000.00

$97,210.28

$91,470.53

$5,739.75

LostRecoveredTotal

Page 33: Phishing: A Direct Deposit to the Criminal World (236905935)

Numbers From Jan/Feb Attack

• 17 Users were victims– 15 Medical Faculty or Staff– 1 Engineering School Faculty– 1 Law Student

• 4 Victims had their Direct Deposit info changed• 7 Users were protected by the Blacklist• 10 Victims were logged into from new IP

addresses which were quickly added to the Blacklist

Page 34: Phishing: A Direct Deposit to the Criminal World (236905935)

How Much $ Did the Criminals Get in January?

• $0 Total was Transferred Out• $0 Was Recovered by Payroll• $0 Was Lost

• Thanks!• Questions?• [email protected]