Lua dao truc tuyen (phishing) gio da tro thanh mot khai niem kha quen
thuoc trong cong dong nguoi dung Internet. Nhung co le khai niem Rock Phish thi
chua duoc pho bien nhu vay
Tuy nhien, cac chuyen gia bao mat khang dinh Rock Phish moi thuc su la moi lo
ngai con hon ca cac vu tan cong phishing. Boi no chinh la goc re cua phan lon
cac vu tan cong phishing, cung nhu la tac gia cua hang loat cac thu doan lua dao
tinh vi.
Rock Phish la...
Dieu dau tien ma ban can biet ve Rock Phish la "hien chua co mot ai biet
chinh xac no la cai gi, hay ai dung dang sau to chuc va van hanh no".
Wikipedia dinh nghia Rock Phish Kit nhu sau: "Mot cong cu kha pho bien duoc
thiet ke voi muc tieu giup cho ca nhung nguoi khong phai dan ky thuat cung co
the thuc hien cac vu tan cong phishing".
Cac chuyen gia bao mat lai cho rang dinh nghia do la hoan toan sai. Ho cho rang
Rock Phish la mot ca nhan hoac mot nhom nguoi co to chuc phai chiu trach nhiem
cho hon mot nua so luong cac vu tan cong phishing da va dang dien ra tren toan
cau.
Thu doan chu yeu cua bon lua dao truc tuyen (phisher) la lua nan nhan cung
cap cho chung cac thong tin ca nhan nhay cam bang cach su dung nhung trang web
gia mao giong het trang web cua mot ngan hang hoac mot cua hang truc tuyen. Day
la mot hinh thuc tan cong rat hap dan doi voi bon toi pham mang, boi nguon loi
nhuan ma no mang ve la rat lon.
Hang nghien cuu Gartner uoc tinh trong nam qua, thiet hai ma lua dao truc tuyen
da gay ra cho nguoi tieu dung va doanh nghiep My da len toi con so 2,8 ti USD.
Tinh trung binh moi nan nhan phai chiu muc thiet hai tuong duong 1.244 USD.
Nhung cho den nay, van chua co mot ai biet Rock Phish la gi, no ton tai o dau va
lieu no chi hoat dong tren mot quoc gia hay lien quoc gia.
"Chung la nhung Keyser Söze cua the gioi phishing," Zulfikar Ramzan -
chuyen gia nghien cuu cao cap cua Symantec Security Response - nhan dinh.
(Keyser Söze la mot nhan vat tru cot cua the gioi toi pham ngam trong bo phim
The Usual Suspects phat hanh nam 1995).
"Bon chung dang tien hanh nhung hanh dong lam kinh hoang cho nguoi dung
Internet tren toan cau".
Lich su cua Rock Phish
Cai ten Rock Phish xuat hien vao cuoi nam 2004. Luc do cai ten nay duoc dat cho
mot nhom toi pham co to chuc cuc ky nguy hiem.
So di chung duoc dat cai ten do la boi vi de qua mat cac cong cu loc phishing,
nhom toi pham nay thuong tao ra mot thu muc co ten "rock" luu tru truc tiep cung
voi cac website gia mao cua chung.
Ke tu do, nhom toi pham nay da phat trien ngay cang manh me va tro thanh mot
trong nhung bang nhom toi pham lua dao truc tuyen "thanh cong nhat" tren the
gioi. Chung lien tuc "phat minh" ra nhieu ky thuat tan cong moi khien cac chuyen
gia bao mat chuyen nghiep cung phai "nguong mo" tai nang cua chung.
Uoc tinh den nay cac thu doan tan cong phishing cua nhom toi pham nay da mang ve
cho chung mot nguon loi nhuan len toi 100 trieu USD.
Phuong thuc hoat dong
Rock Phish khong phai noi tieng vi viec chuyen tan cong vao hai muc tieu duoc ua
chuong nhat la eBay va PayPal, ma thay vao do chung chuyen tan cong vao cac to
chuc tai chinh cua My va Chau Au.
Con so thong ke moi nhat cho thay Rock Phish da gia mao 44 thuong hieu cua cac
doanh nghiep tai 9 quoc gia khac nhau va gui di vo so email mao danh, nham lua
nan nhan truy cap vao mot trong nhung website gia mao va cung cap cho chung
nhung thong tin bi mat nhu so the tin dung, tai khoan ngan hang truc tuyen ...
Rock Phish chua tung "tha" cho "mot con moi" nao, tu Barclays, Citibank,
Deutsche Bank, E-Trade den hang tram doanh nghiep thanh toan truc tuyen khac.
Cac chuyen gia bao mat uoc tinh Roch Phish co dinh dang den gan 1/2 so luong
email lua dao duoc gui di tren mang Internet. "Chung la nhom toi pham lua
dao truc tuyen "nang dong" nhat tren the gioi," Dan Hubbard - Giam doc
nghien cuu cong nghe va bao mat cua Websense - nhan dinh.
Dieu khien cac chuyen gia bao mat nhu Dan Hubbard phai lo ngai nhat ve Rock
Phish la nhom toi pham nay luon di truoc mot buoc so voi cac san pham bao mat va
luat phap.
Lay vi du, cac chuyen gia bao mat cho biet Rock Phish chinh la ke di dau trong
viec gui spam bang hinh anh nham qua mat cac cong cu loc thu rac. Roi trong khi
cac hang phan mem tich hop cong cu loc phishing vao trong trinh duyet thi nhom
toi pham nay da "sang tao" ra nhung kieu duong dan URL dac biet giup chung khong
bi "diem danh" trong "danh sach den" cac URL phishing.
Chuyen gia Ramzan cua Symantec lac dau ngao ngan cho biet kieu dia chi
website "dung mot lan" nhu kieu cua Rock Phish khien chung that su rat kho bi
phat hien. Nhieu khi cac chuyen gia bao mat cung phai bo tay trong viec ngan
chan nhung trang web kieu nay.
Voi kieu su dung co so du lieu danh sach cac dia chi phishing nhu trinh duyet
Firefox thi viec bi Rock Phish qua mat la chuyen nhu com bua. "Noi rong hon
la nhung cong nghe chong phishing dua tren danh sach den la hoan toan vo dung,"
Ramzan nhan manh.
Anti-Phishing Working Group cho biet trong thoi gian gan day Rock Phish van tiep
tuc gop phan lam gia tang manh me so luong cac trang web phishing tren toan cau.
Thang 8, nhom toi pham nay da phat tan hon 19.000 dia chi website phishing. Con
so nay lai tang gap doi trong thang 10 vua qua voi hon 35.000 dia chi.
Cac chuyen gia bao mat cho rang Rock Phish duoc dieu hanh boi mot nhom nho nhung
ten toi pham mang co trinh do ky thuat cao. Uoc tinh so luong cua chung chi vao
khoang mot chuc nguoi. Nhung day moi chinh la nhung ke dau nao boi trach nhiem
cua chung la tao ra cac trang web phishing, quan ly ten mien va bao dam cac
thong tin tai chinh an cap duoc deu duoc gui ve mot may chu trung tam. Cac
chuyen gia bao mat goi cai may chu do la "Mother Ship" (tau me).
Nhung thong tin ma chung an cap duoc sau do se duoc rao ban tren cac chatroom.
Doi tuong tieu thu "hang" cua bon chung chu yeu la nhung ke rua tien giup bien
nhung dong tien an cap thanh tien sach.
"Minh tinh" cua the gioi phishing
Rock Phish su dung mot he thong mang cac PC bi "bat coc" de chuyen huong khach
truy cap den trang cua chung ve "Mother Ship".
Mot yeu to dac biet nguy hiem khac trong phuong thuc hoat dong cua Rock Phish la
nhom toi pham nay da ap dung phuong thuc hoat dong phi tap trung hoa trong cac
hoat dong pham phap.
Thu doan duoc xem la thanh cong nhat cua bon chung la Rock Phish thuong xuyen su
dung ten mien cua cac quoc gia it duoc biet den nhu ten mien ".md" cua Moldovia
boi nhung quoc gia nhu the nay hau nhu chua co luat chong lai phishing. Chinh lo
hong nay da tao dieu kien cho su phat trien manh me cua Rock Phish.
"Rock Phish la nhung nha hoat dong vi doi moi trong the gioi phishing,"
chuyen gia Ramzan cua Symantec thua nhan. "Bat cu khi nao chung ta thay xuat
hien mot ky thuat tan cong phishing moi thi chac chan do la tac pham cua Rock
Phish".
Theo PC World, VietNamNet
Article source http://w4rum.com/474.t
|