Attacks/Breaches
10/22/2012
04:52 PM
Connect Directly
RSS
E-Mail
50%
50%

Who Is Hacking U.S. Banks? 8 Facts

Hackers have labeled the bank website disruptions as grassroots-level reprisal for an anti-Islamic film. But is the Iranian government really backing the attacks?
Previous
1 of 8
Next


Who's behind the recent online attacks against U.S. banks? A Muslim hacktivist group calling itself the Cyber fighters of Izz ad-din Al qassam continues to take credit for the campaign of website disruptions. In recent weeks, its distributed denial-of-service (DDoS) attacks, launched under the banner of "Operation Ababil," have disrupted the websites of some of Wall Street's biggest financial institutions, including Bank of America, BB&T, JPMorgan Chase, Capital One, HSBC, New York Stock Exchange, Regions Financial, SunTrust, U.S. Bank, and Wells Fargo.

The hacktivist group's name refers to "Izz ad-Din al-Qassam, a Muslim holy man who fought against European forces and Jewish settlers in the Middle East in the 1920s and 1930s," according to The New York Times. In a similar vein, the website disruptions have been portrayed by some backers as a spontaneous, grassroots-driven online protest. But the actual identity of the attackers, as well as their motives or backing, remain the subject of much debate. Notably, U.S. officials--speaking anonymously in media interviews--have alleged that the group, despite what its own anonymous public pronouncements might claim, is nothing more than a front for an operation that's being run by the Iranian government.

In a series of Pastebin posts, the hacktivists have typically previewed which banks they'll be disrupting, as well as the dates and times of planned attacks. At the same time, they've broadly denied U.S. government officials' assertions, including allegations that the group has been involved in recent attacks that employed malware to obtain credentials for U.S. bank websites, allowing attackers to wire money from U.S. to overseas bank accounts, stealing up to $900,000 in one go.

So, what do the attackers want? According to their Pastebin pronouncements, their goal is relatively simple: they want to see the Innocence of Muslims film that mocks the founder of Islam removed from the Internet. A 14-minute clip of the film first surfaced on YouTube in July 2012, parts of which were broadcast on Egyptian television on Sept. 9, 2012.

The film has been attributed to Nakoula Basseley Nakoula (a.k.a. Mark Basseley Youssef), 55, who was recently arrested in the United States on parole violations, which could see him returned to jail for two years. Nakoula, an Egyptian-born U.S. resident, was on parole after serving prison time for his 2010 conviction on bank fraud charges, and his alleged parole violations include using aliases, using a computer without supervision, and lying to his probation officer. Nakoula, however, has denied all charges against him. He's due back in court next month.

In the meantime, the attacks on banking websites show no signs of stopping.

Image credit: Photograph of Wall Street courtesy of Flickr user Michael Daddino.

Previous
1 of 8
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Leo Regulus
50%
50%
Leo Regulus,
User Rank: Apprentice
10/24/2012 | 4:52:32 PM
re: Who Is Hacking U.S. Banks? 8 Facts
Very disappointed in Editor's choice of article format. This has been extensively discussed in the past.
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Must Reads - September 25, 2014
Dark Reading's new Must Reads is a compendium of our best recent coverage of identity and access management. Learn about access control in the age of HTML5, how to improve authentication, why Active Directory is dead, and more.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-6856
Published: 2014-10-02
The AHRAH (aka com.vet2pet.aid219426) application 219426 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-6857
Published: 2014-10-02
The Car Wallpapers HD (aka com.arab4x4.gallery.app) application 1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-6858
Published: 2014-10-02
The Mostafa Shemeas (aka com.mostafa.shemeas.website) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-6859
Published: 2014-10-02
The Daum Maps - Subway (aka net.daum.android.map) application 3.9.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-6860
Published: 2014-10-02
The Trial Tracker (aka com.etcweb.android.trial_tracker) application 1.1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Chris Hadnagy, who hosts the annual Social Engineering Capture the Flag Contest at DEF CON, will discuss the latest trends attackers are using.