Download - Phishing: A Direct Deposit to the Criminal World (236905935)

Transcript
Page 1: Phishing: A Direct Deposit to the Criminal World (236905935)

Direct Deposit Phishing Attack

Brian [email protected]

Network Security AnalystWashington University in Saint Louis

May 2014

Page 2: Phishing: A Direct Deposit to the Criminal World (236905935)

Topics for Today

• Brief overview of the Washington University network

• Brief look at first incident in Sept/Oct 2013• Brief look at second incident in Jan/Feb 2014• Potential phishing defenses• Some examples of real phishing emails• Who attacked us?• Final thoughts

Page 3: Phishing: A Direct Deposit to the Criminal World (236905935)

Washington University in St. Louis

NSS

NSO

Business School

Law School

Arts & Sciences

Medical School

Engineering School

Internet

Decentralized Campus NetworkNSS = Network Services and SupportNSO = Network Security Office

Library

Social Work

Art & Architecture

Page 4: Phishing: A Direct Deposit to the Criminal World (236905935)

Numbers from Sept/Oct 2013 Attack:

• 13 total victims• 11 Medical School faculty• 2 Business School faculty• 11 had direct deposit info changed• 1 account caught by the new HRMS blacklist

and immediately blocked

Page 5: Phishing: A Direct Deposit to the Criminal World (236905935)

Round 1a Phishing Attack

Page 6: Phishing: A Direct Deposit to the Criminal World (236905935)

Round 1b Phishing Email

Page 7: Phishing: A Direct Deposit to the Criminal World (236905935)
Page 8: Phishing: A Direct Deposit to the Criminal World (236905935)

Numbers From Jan/Feb 2014 Attack

• 17 Users were victims– 15 Medical Faculty or Staff– 1 Engineering School Faculty– 1 Law Student

• 4 Victims had their Direct Deposit info changed• 7 Users were protected by the Blacklist• 10 Victims were logged into from new IP

addresses which were quickly added to the Blacklist

Page 9: Phishing: A Direct Deposit to the Criminal World (236905935)

Round 2 Phish Three Months Later

Page 10: Phishing: A Direct Deposit to the Criminal World (236905935)
Page 11: Phishing: A Direct Deposit to the Criminal World (236905935)
Page 12: Phishing: A Direct Deposit to the Criminal World (236905935)

Criminals seemingly have a huge advantage

They send hundreds of phishing emails and only need ONE user to fall

for it to succeed

Page 13: Phishing: A Direct Deposit to the Criminal World (236905935)

We can turn the tables on them

Force the criminal to run througha gauntlet of defenses to succeed

Page 14: Phishing: A Direct Deposit to the Criminal World (236905935)

Reconnaissance Phase

Page 15: Phishing: A Direct Deposit to the Criminal World (236905935)

Phishing Email Phase

Page 16: Phishing: A Direct Deposit to the Criminal World (236905935)

Criminal Login Phase

Page 17: Phishing: A Direct Deposit to the Criminal World (236905935)

HR/SSO Application Suggestions

Page 18: Phishing: A Direct Deposit to the Criminal World (236905935)

Payroll Alerting Suggestions

Page 19: Phishing: A Direct Deposit to the Criminal World (236905935)

Communication Suggestions

Page 20: Phishing: A Direct Deposit to the Criminal World (236905935)

Phishing Examples

Page 21: Phishing: A Direct Deposit to the Criminal World (236905935)

WUSTL Site or Phish Site?

Page 22: Phishing: A Direct Deposit to the Criminal World (236905935)
Page 23: Phishing: A Direct Deposit to the Criminal World (236905935)

WUSTL Site or Phish Site?

Page 24: Phishing: A Direct Deposit to the Criminal World (236905935)
Page 25: Phishing: A Direct Deposit to the Criminal World (236905935)

WUSTL Site or Phish Site?

Page 26: Phishing: A Direct Deposit to the Criminal World (236905935)

Real Email or Phish Email?

Page 27: Phishing: A Direct Deposit to the Criminal World (236905935)
Page 28: Phishing: A Direct Deposit to the Criminal World (236905935)

Spammers log in and useaccount to send spam

Page 29: Phishing: A Direct Deposit to the Criminal World (236905935)

Sept/Oct Attack 1

Page 30: Phishing: A Direct Deposit to the Criminal World (236905935)

Jan/Feb Attack

Page 31: Phishing: A Direct Deposit to the Criminal World (236905935)

Numbers from September/October:

• 13 total victims• 11 Medical School faculty• 2 Business School faculty• 11 had direct deposit info changed• 1 account caught by the new HRMS blacklist

and immediately blocked

Page 32: Phishing: A Direct Deposit to the Criminal World (236905935)

How Much $ Did the Criminals Get in October?

• $97,210.28 Total was Transferred Out• $91,470.53 Was Recovered by Payroll• $5,739.75 Was Lost

.

$0.00

$20,000.00

$40,000.00

$60,000.00

$80,000.00

$100,000.00

$120,000.00

$97,210.28

$91,470.53

$5,739.75

LostRecoveredTotal

Page 33: Phishing: A Direct Deposit to the Criminal World (236905935)

Numbers From Jan/Feb Attack

• 17 Users were victims– 15 Medical Faculty or Staff– 1 Engineering School Faculty– 1 Law Student

• 4 Victims had their Direct Deposit info changed• 7 Users were protected by the Blacklist• 10 Victims were logged into from new IP

addresses which were quickly added to the Blacklist

Page 34: Phishing: A Direct Deposit to the Criminal World (236905935)

How Much $ Did the Criminals Get in January?

• $0 Total was Transferred Out• $0 Was Recovered by Payroll• $0 Was Lost

• Thanks!• Questions?• [email protected]