Attacks/Breaches
10/22/2012
04:52 PM
50%
50%

Who Is Hacking U.S. Banks? 8 Facts

Hackers have labeled the bank website disruptions as grassroots-level reprisal for an anti-Islamic film. But is the Iranian government really backing the attacks?
Previous
1 of 8
Next


Who's behind the recent online attacks against U.S. banks? A Muslim hacktivist group calling itself the Cyber fighters of Izz ad-din Al qassam continues to take credit for the campaign of website disruptions. In recent weeks, its distributed denial-of-service (DDoS) attacks, launched under the banner of "Operation Ababil," have disrupted the websites of some of Wall Street's biggest financial institutions, including Bank of America, BB&T, JPMorgan Chase, Capital One, HSBC, New York Stock Exchange, Regions Financial, SunTrust, U.S. Bank, and Wells Fargo.

The hacktivist group's name refers to "Izz ad-Din al-Qassam, a Muslim holy man who fought against European forces and Jewish settlers in the Middle East in the 1920s and 1930s," according to The New York Times. In a similar vein, the website disruptions have been portrayed by some backers as a spontaneous, grassroots-driven online protest. But the actual identity of the attackers, as well as their motives or backing, remain the subject of much debate. Notably, U.S. officials--speaking anonymously in media interviews--have alleged that the group, despite what its own anonymous public pronouncements might claim, is nothing more than a front for an operation that's being run by the Iranian government.

In a series of Pastebin posts, the hacktivists have typically previewed which banks they'll be disrupting, as well as the dates and times of planned attacks. At the same time, they've broadly denied U.S. government officials' assertions, including allegations that the group has been involved in recent attacks that employed malware to obtain credentials for U.S. bank websites, allowing attackers to wire money from U.S. to overseas bank accounts, stealing up to $900,000 in one go.

So, what do the attackers want? According to their Pastebin pronouncements, their goal is relatively simple: they want to see the Innocence of Muslims film that mocks the founder of Islam removed from the Internet. A 14-minute clip of the film first surfaced on YouTube in July 2012, parts of which were broadcast on Egyptian television on Sept. 9, 2012.

The film has been attributed to Nakoula Basseley Nakoula (a.k.a. Mark Basseley Youssef), 55, who was recently arrested in the United States on parole violations, which could see him returned to jail for two years. Nakoula, an Egyptian-born U.S. resident, was on parole after serving prison time for his 2010 conviction on bank fraud charges, and his alleged parole violations include using aliases, using a computer without supervision, and lying to his probation officer. Nakoula, however, has denied all charges against him. He's due back in court next month.

In the meantime, the attacks on banking websites show no signs of stopping.

Image credit: Photograph of Wall Street courtesy of Flickr user Michael Daddino.

Previous
1 of 8
Next
Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
Leo Regulus
50%
50%
Leo Regulus,
User Rank: Apprentice
10/24/2012 | 4:52:32 PM
re: Who Is Hacking U.S. Banks? 8 Facts
Very disappointed in Editor's choice of article format. This has been extensively discussed in the past.
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This is a secure windows pc.
Current Issue
Security Operations and IT Operations: Finding the Path to Collaboration
A wide gulf has emerged between SOC and NOC teams that's keeping both of them from assuring the confidentiality, integrity, and availability of IT systems. Here's how experts think it should be bridged.
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.

Dark Reading Radio
Archived Dark Reading Radio
In past years, security researchers have discovered ways to hack cars, medical devices, automated teller machines, and many other targets. Dark Reading Executive Editor Kelly Jackson Higgins hosts researcher Samy Kamkar and Levi Gundert, vice president of threat intelligence at Recorded Future, to discuss some of 2016's most unusual and creative hacks by white hats, and what these new vulnerabilities might mean for the coming year.