Attacks/Breaches
10/22/2012
04:52 PM
Connect Directly
RSS
E-Mail
50%
50%

Who Is Hacking U.S. Banks? 8 Facts

Hackers have labeled the bank website disruptions as grassroots-level reprisal for an anti-Islamic film. But is the Iranian government really backing the attacks?
Previous
1 of 8
Next


Who's behind the recent online attacks against U.S. banks? A Muslim hacktivist group calling itself the Cyber fighters of Izz ad-din Al qassam continues to take credit for the campaign of website disruptions. In recent weeks, its distributed denial-of-service (DDoS) attacks, launched under the banner of "Operation Ababil," have disrupted the websites of some of Wall Street's biggest financial institutions, including Bank of America, BB&T, JPMorgan Chase, Capital One, HSBC, New York Stock Exchange, Regions Financial, SunTrust, U.S. Bank, and Wells Fargo.

The hacktivist group's name refers to "Izz ad-Din al-Qassam, a Muslim holy man who fought against European forces and Jewish settlers in the Middle East in the 1920s and 1930s," according to The New York Times. In a similar vein, the website disruptions have been portrayed by some backers as a spontaneous, grassroots-driven online protest. But the actual identity of the attackers, as well as their motives or backing, remain the subject of much debate. Notably, U.S. officials--speaking anonymously in media interviews--have alleged that the group, despite what its own anonymous public pronouncements might claim, is nothing more than a front for an operation that's being run by the Iranian government.

In a series of Pastebin posts, the hacktivists have typically previewed which banks they'll be disrupting, as well as the dates and times of planned attacks. At the same time, they've broadly denied U.S. government officials' assertions, including allegations that the group has been involved in recent attacks that employed malware to obtain credentials for U.S. bank websites, allowing attackers to wire money from U.S. to overseas bank accounts, stealing up to $900,000 in one go.

So, what do the attackers want? According to their Pastebin pronouncements, their goal is relatively simple: they want to see the Innocence of Muslims film that mocks the founder of Islam removed from the Internet. A 14-minute clip of the film first surfaced on YouTube in July 2012, parts of which were broadcast on Egyptian television on Sept. 9, 2012.

The film has been attributed to Nakoula Basseley Nakoula (a.k.a. Mark Basseley Youssef), 55, who was recently arrested in the United States on parole violations, which could see him returned to jail for two years. Nakoula, an Egyptian-born U.S. resident, was on parole after serving prison time for his 2010 conviction on bank fraud charges, and his alleged parole violations include using aliases, using a computer without supervision, and lying to his probation officer. Nakoula, however, has denied all charges against him. He's due back in court next month.

In the meantime, the attacks on banking websites show no signs of stopping.

Image credit: Photograph of Wall Street courtesy of Flickr user Michael Daddino.

Previous
1 of 8
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Leo Regulus
50%
50%
Leo Regulus,
User Rank: Apprentice
10/24/2012 | 4:52:32 PM
re: Who Is Hacking U.S. Banks? 8 Facts
Very disappointed in Editor's choice of article format. This has been extensively discussed in the past.
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-2595
Published: 2014-08-31
The device-initialization functionality in the MSM camera driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, enables MSM_CAM_IOCTL_SET_MEM_MAP_INFO ioctl calls for an unrestricted mmap interface, which all...

CVE-2013-2597
Published: 2014-08-31
Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via an application that lever...

CVE-2013-2598
Published: 2014-08-31
app/aboot/aboot.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to overwrite signature-verification code via crafted boot-image load-destination header values that specify memory ...

CVE-2013-2599
Published: 2014-08-31
A certain Qualcomm Innovation Center (QuIC) patch to the NativeDaemonConnector class in services/java/com/android/server/NativeDaemonConnector.java in Code Aurora Forum (CAF) releases of Android 4.1.x through 4.3.x enables debug logging, which allows attackers to obtain sensitive disk-encryption pas...

CVE-2013-6124
Published: 2014-08-31
The Qualcomm Innovation Center (QuIC) init scripts in Code Aurora Forum (CAF) releases of Android 4.1.x through 4.4.x allow local users to modify file metadata via a symlink attack on a file accessed by a (1) chown or (2) chmod command, as demonstrated by changing the permissions of an arbitrary fil...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
This episode of Dark Reading Radio looks at infosec security from the big enterprise POV with interviews featuring Ron Plesco, Cyber Investigations, Intelligence & Analytics at KPMG; and Chris Inglis & Chris Bell of Securonix.