Risk
9/9/2013
10:48 AM
50%
50%

Nigerian Scam Keylogger Tactics Exposed

Hacker shares look into PrivateRecovery service, which offers would-be scammers customized keyloggers disguised as screen savers.

Want to become a Nigerian scammer? Then turn to a website named PrivateRecovery -- formerly known as BestRecovery -- which offers scamware-as-a-service tools for just $25 to $33 per month.

That information comes by way of security reporter Brian Krebs, who said that an unnamed gray hat hacker had retrieved and shared with him a list of about 3,000 users of PrivateRecovery. The site offers its customers customized keylogging software disguised as a screensaver. Users try to trick their victims into using the malicious software, which records sensitive financial and personal information from victims' PCs. Criminals then retrieve the stolen information via the PrivateRecovery site.

Unfortunately for users of PrivateRecovery, however, the website itself lacks basic information security safeguards. "The site was so poorly locked down that it also exposed the keylog records that customers kept on the service. Logs were indexed and archived each month, and most customers used the service to keep tabs on multiple computers in several countries," Krebs said. "A closer look at the logs revealed that a huge number of the users appear to be Nigerian 419 scammers using computers with Internet addresses in Nigeria."

[ Is the SEA getting help from Iran? Read FBI Warns Of Syrian Electronic Army Hacking Threat. ]

Who uses PrivateRecovery? "The first thing I noticed upon viewing the user list was that a majority of this service's customers had signed up with yahoo.com emails, and appeared to have African-sounding usernames or email addresses," Krebs said. The user list included numerous email addresses that had been flagged as being used in scams. "Running a simple online search for some of the user emails (dittoswiss@yahoo.com, for example) turned up complaints related to a variety of lottery, dating, reshipping and confidence scams."

Interestingly, some of the keylogger data being stored on the PrivateRecovery site showed that registered users were themselves victims of the site's keylogging software attacks, which suggests that rival scammers may be targeting each other. One likely explanation is that some users have been infecting with keylogging software PCs in Internet cafes from which 419 scammers are known to operate.

Regardless of their victims' identities, PrivateRecovery users appear to be behind a number of Nigerian letter scams, aka "advance fee fraud" or 419 scams, which refers to a section of the Nigerian penal code criminalizing fraud.

Many such scams follow this broad template: The email sender needs money quickly and in return promises future outsize rewards. For example, one message making the rounds Monday -- which even included a calendar attachment notifying the recipient of an impending meeting about the deal -- promised 10% of a contested $37.5 million inheritance and 30% of any profits if the recipient would help move the money from a bank in Sierra Leone to Ivory Coast. "So please i am asking you to send to me your banking informations (sic) as to enable me send it to the bank for introduction of your person as the one to whom the money has to be transferred to for investment in your country which you have to be in control while i (sic) further my education," promised the sender.

Not coincidentally, Ivory Coast is reported to be one hotbed for Nigerian scam operators. Others include India, the Netherlands, Russia, South Africa and Spain.

Why does this far-fetched-sounding fraud persist? As demonstrated by recent FBI alerts, the simple answer is that scammers continue to score more victims using a cheap and easy attack. But this is hardly a new development. Indeed, modern 419 scams were preceded by a late 19th-century "Spanish Prisoner" scam in which a letter writer sought a small investment to help free a wealthy friend -- whose identity, for safety reasons, couldn't be revealed -- in return for a generous reward upon his friend's release. Even prior to that, a "Letter From Jerusalem" seen as early as the 1830s promised generous rewards in exchange for retrieving "a casket containing 16,000 francs in gold and the diamonds of a late marchioness."

As that suggests, regardless of the technological medium -- and throughout history -- human psychology has remained far too easy to hack.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
anon9140401815
100%
0%
anon9140401815,
User Rank: Apprentice
5/15/2014 | 5:03:00 AM
How to monitor a PC
Micro Keylogger records almost all the activities on the computer. Not like other so-called invisible keyloggers, Micro Keylogger is invisible from Desktop, Start Menu, Task Bar and more. It runs in stealth and won't have any impact on the system performance.
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-4440
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 generates weak non-tty passwords, which makes it easier for context-dependent attackers to guess the password via a brute-force attack.

CVE-2013-4442
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 uses weak pseudo generated numbers when /dev/urandom is unavailable, which makes it easier for context-dependent attackers to guess the numbers.

CVE-2013-7401
Published: 2014-12-19
The parse_request function in request.c in c-icap 0.2.x allows remote attackers to cause a denial of service (crash) via a URI without a " " or "?" character in an ICAP request, as demonstrated by use of the OPTIONS method.

CVE-2014-2026
Published: 2014-12-19
Cross-site scripting (XSS) vulnerability in the search functionality in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to inject arbitrary web script or HTML via the request parameter.

CVE-2014-2716
Published: 2014-12-19
Ekahau B4 staff badge tag 5.7 with firmware 1.4.52, Real-Time Location System (RTLS) Controller 6.0.5-FINAL, and Activator 3 reuses the RC4 cipher stream, which makes it easier for remote attackers to obtain plaintext messages via an XOR operation on two ciphertexts.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.