Risk
9/9/2013
10:48 AM
50%
50%

Nigerian Scam Keylogger Tactics Exposed

Hacker shares look into PrivateRecovery service, which offers would-be scammers customized keyloggers disguised as screen savers.

Want to become a Nigerian scammer? Then turn to a website named PrivateRecovery -- formerly known as BestRecovery -- which offers scamware-as-a-service tools for just $25 to $33 per month.

That information comes by way of security reporter Brian Krebs, who said that an unnamed gray hat hacker had retrieved and shared with him a list of about 3,000 users of PrivateRecovery. The site offers its customers customized keylogging software disguised as a screensaver. Users try to trick their victims into using the malicious software, which records sensitive financial and personal information from victims' PCs. Criminals then retrieve the stolen information via the PrivateRecovery site.

Unfortunately for users of PrivateRecovery, however, the website itself lacks basic information security safeguards. "The site was so poorly locked down that it also exposed the keylog records that customers kept on the service. Logs were indexed and archived each month, and most customers used the service to keep tabs on multiple computers in several countries," Krebs said. "A closer look at the logs revealed that a huge number of the users appear to be Nigerian 419 scammers using computers with Internet addresses in Nigeria."

[ Is the SEA getting help from Iran? Read FBI Warns Of Syrian Electronic Army Hacking Threat. ]

Who uses PrivateRecovery? "The first thing I noticed upon viewing the user list was that a majority of this service's customers had signed up with yahoo.com emails, and appeared to have African-sounding usernames or email addresses," Krebs said. The user list included numerous email addresses that had been flagged as being used in scams. "Running a simple online search for some of the user emails (dittoswiss@yahoo.com, for example) turned up complaints related to a variety of lottery, dating, reshipping and confidence scams."

Interestingly, some of the keylogger data being stored on the PrivateRecovery site showed that registered users were themselves victims of the site's keylogging software attacks, which suggests that rival scammers may be targeting each other. One likely explanation is that some users have been infecting with keylogging software PCs in Internet cafes from which 419 scammers are known to operate.

Regardless of their victims' identities, PrivateRecovery users appear to be behind a number of Nigerian letter scams, aka "advance fee fraud" or 419 scams, which refers to a section of the Nigerian penal code criminalizing fraud.

Many such scams follow this broad template: The email sender needs money quickly and in return promises future outsize rewards. For example, one message making the rounds Monday -- which even included a calendar attachment notifying the recipient of an impending meeting about the deal -- promised 10% of a contested $37.5 million inheritance and 30% of any profits if the recipient would help move the money from a bank in Sierra Leone to Ivory Coast. "So please i am asking you to send to me your banking informations (sic) as to enable me send it to the bank for introduction of your person as the one to whom the money has to be transferred to for investment in your country which you have to be in control while i (sic) further my education," promised the sender.

Not coincidentally, Ivory Coast is reported to be one hotbed for Nigerian scam operators. Others include India, the Netherlands, Russia, South Africa and Spain.

Why does this far-fetched-sounding fraud persist? As demonstrated by recent FBI alerts, the simple answer is that scammers continue to score more victims using a cheap and easy attack. But this is hardly a new development. Indeed, modern 419 scams were preceded by a late 19th-century "Spanish Prisoner" scam in which a letter writer sought a small investment to help free a wealthy friend -- whose identity, for safety reasons, couldn't be revealed -- in return for a generous reward upon his friend's release. Even prior to that, a "Letter From Jerusalem" seen as early as the 1830s promised generous rewards in exchange for retrieving "a casket containing 16,000 francs in gold and the diamonds of a late marchioness."

As that suggests, regardless of the technological medium -- and throughout history -- human psychology has remained far too easy to hack.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
anon9140401815
100%
0%
anon9140401815,
User Rank: Apprentice
5/15/2014 | 5:03:00 AM
How to monitor a PC
Micro Keylogger records almost all the activities on the computer. Not like other so-called invisible keyloggers, Micro Keylogger is invisible from Desktop, Start Menu, Task Bar and more. It runs in stealth and won't have any impact on the system performance.
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-5208
Published: 2014-12-22
BKBCopyD.exe in the Batch Management Packages in Yokogawa CENTUM CS 3000 through R3.09.50 and CENTUM VP through R4.03.00 and R5.x through R5.04.00, and Exaopc through R3.72.10, does not require authentication, which allows remote attackers to read arbitrary files via a RETR operation, write to arbit...

CVE-2014-7286
Published: 2014-12-22
Buffer overflow in AClient in Symantec Deployment Solution 6.9 and earlier on Windows XP and Server 2003 allows local users to gain privileges via unspecified vectors.

CVE-2014-8015
Published: 2014-12-22
The Sponsor Portal in Cisco Identity Services Engine (ISE) allows remote authenticated users to obtain access to an arbitrary sponsor's guest account via a modified HTTP request, aka Bug ID CSCur64400.

CVE-2014-8017
Published: 2014-12-22
The periodic-backup feature in Cisco Identity Services Engine (ISE) allows remote attackers to discover backup-encryption passwords via a crafted request that triggers inclusion of a password in a reply, aka Bug ID CSCur41673.

CVE-2014-8018
Published: 2014-12-22
Multiple cross-site scripting (XSS) vulnerabilities in Business Voice Services Manager (BVSM) pages in the Application Software in Cisco Unified Communications Domain Manager 8 allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCur19651, CSCur18555, CSCur1...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.