Remember Me
forgot your password?

How Keylogging Software Allows Cybercriminals to Steal your Passwords Silently

A ring of cybercriminals recently broken up by Russian authorities used keylogging software planted in e-mail messages and hidden in websites to draw over $1.1 million from personal bank accounts in France.

The goal of these cybercriminals was to infect the inner workings of computers in much the same way that mischief-making virus writers do. The twist here is that the keylogging programs exploit security flaws and monitor the path that carries data from the keyboard to other parts of the computer. This is a more invasive approach than phishing, which relies on deception rather than infection, tricking people into giving their information to a fake website.

The keylogging programs are often hidden inside ordinary software downloads, e-mail attachments, or files shared over peer-to-peer networks. Because they can be embedded in webpages, they take advantage of browser features that allow programs to run automatically.

The hidden keylogging programs infect the computers of unsuspecting users. This puts the keylogging programs in the category of malicious programs known as Trojan horses, or just Trojans. These Trojans are very selective because they monitor the web access the victims make, and start recording information only when the user enters the sites of interest to the fraudster.

In some countries the use of keylogging programs that silently copy the keystrokes of computer users and send that information to the crooks has surpassed "phishing" messages, those that pretend to be from a bank or business but are actually attempts to steal passwords and other personal information. Among global cybercriminals, phishing may already be passé.

In Brazil, cybercriminal have given up traditional phishing for the easier and more profitable keylogging activities. According to data compiled by computer security companies in 2005, the use of "crimeware" like keyloggers to steal user names and passwords — and ultimately cash — has soared. The crimes often cross international borders, and they put Internet users everywhere at risk.

"It's the wave of the future," according Peter Cassidy, the Secretary General of the Anti-Phishing Working Group, a consortium of industry and law enforcement partners that fights online fraud and identity theft. "All this stuff is becoming more and more automated and more and more opaque."

Mr. Cassidy's group found that the number of Web sites known to be hiding this kind of malicious code nearly doubled between November and December, rising to more than 1,900. The antivirus company Symantec has reported that half of the malicious software it tracks is designed not to damage computers but to gather personal data.

Over the course of 2005, iDefense, a unit of Verisign that provides information on computer security to government and industry clients, counted over 6,000 different keylogger variants — a 65 percent increase over 2004. About one-third of all malicious code tracked by the company now contains some keylogging component, according to Ken Dunham, the company's rapid-response director.

And the SANS Institute, a group that trains and certifies computer security professionals, estimated that at a single moment last fall, as many as 9.9 million machines in the United States were infected with keyloggers of one kind or another, putting as much as $24 billion in bank account assets — and probably much more — literally at the fingertips of fraudsters. John Bambenek, the SANS researcher who made the estimate, suggested that the infection rate was probably much higher.

In most cases, a keylogger or similar program, once installed, will simply wait for certain Web sites to be visited — a banking site, for instance, or a credit card account online — or for certain keywords to be entered — "SSN," for example — and then spring to life.

Keystrokes are saved to a file, Web forms are copied — even snapshots of a user's screen can be silently recorded. The information is then sent back to a website or some waiting server where a thief, or a different piece of software, sifts through the data for useful nuggets.

The Federal Deposit Insurance Corporation, responding to the growing threat of cybercrime to the financial industry, stiffened its guidelines for Internet banking in October, effectively ordering banks to do more than ask for a simple user name and password. But it stopped short of requiring, for instance, the use of electronic devices that generate numeric passcodes every 60 seconds, which many experts say would help foil much online fraud, including the use of keyloggers.

Technology for grabbing text and screen images is not new — or particularly sophisticated. Keyloggers are even sold commercially, as tools for keeping an eye on what children are doing online, or what a spouse might be doing in online chat rooms. And while most experts agree that data-swiping software is spreading rapidly, there are some who say the problem has been exaggerated.

Some words to the wise: Being wary of unfamiliar weblinks sent via e-mail is a first-line of defense, according to experts, as are avoiding questionable downloads and keeping up to date with Windows patches and antivirus updates.

It is worth noting, however, that in a test of major antivirus programs conducted in Brazil last fall, the very best detected only 88 percent of the known keyloggers flourishing there. In the United States, on the other hand, victims of fraudulent money transfers are typically limited to $50 in liability under the Federal Reserve's Regulation E, so long as they report the crime quickly enough — within two days. If they report it within 60 days, their liability is capped at $500.

Because cybercriminals are becoming smarter and more sophisticated in their operations, they are real threats to your personal security and privacy. Your money, your computer, your family, and your business are all at risk. These cybercriminals leave you with three choices: (1) Do nothing and hope their attacks, risks, and threats don’t occur on your computer. (2) Do research and get training to protect yourself, your family, and your business. (3) Get professional help to lockdown your system from all their attacks, risks, and threats.

Remember: When you say "No!" to hackers and spyware, everyone wins! When you don't, we all lose!

Etienne A. Gibbs, MSW

Etienne A. Gibbs, Independent Internet Security Advocate, consults with individuals, small business owners, and home-business entrepreneurs regarding online protection against spyware, viruses, malware, hackers, and other cybercrimes and pc-disabling issues. For more information, visit www.SayNotoHackersandSpyware.com/.

Rate this Article: 0 / 5 stars - 0 vote(s)
Print Email Re-Publish

Add new Comment



Captcha
0
1. Paul Stanley Carter (11:01, 16.11.2008)
What this good information revealed, where do I begin educating myself in defending my information? Learning about what? Deploying what anti programs? And when I mean education, I mean what can I do manually if necessary to scan or search or detect those malicious keyloggers or keystroke software programs? Are those keylogging spyware deposited as "cookies" via computer or pc?

Thanks, I will visit the website or link above for more information! By the way, can articles like this one be a set up for keylogging or keystroke spying? (laughing out loud)

  • Latest Technology Articles
  • More from Etienne A. Gibbs, MSW

CNC Router for Sign Making, CNC plasma cutting, Engraving, and Vinyl Cuttting

By: Christine Frazer | 02/12/2009
http://www.Sign-CNC-Router.com - Get a $1,000 Discount on the purchase of a Techno CNC router! CNC Router for Sign Making, CNC plasma cutting, Engraving, and SNC Vinyl Cuttting

Do you want to trace a Telephone Number on the We? It's very easy now

By: Van Albert | 02/12/2009
Receiving a message from someone you do not know can be pretty annoying. It is especially aggravating to receive strange phone calls from unknown callers. If this ever happens, you could try tracing the number. It is easier to trace a telephone number than it is a mobile phone number---all you need to do is visit a convenient website that contains a database on many numbers and addresses, which are often provided by the telephone companies themselves.

Your Local Store For PSP Go Games Now Is Past - PSP Go Downloads For Unlimited Download PSP Go Games, Movies, Software, And More

By: Dimitar Mishev | 02/12/2009
Do you want to get your favorite games, movies, music, software, themes, and more for your PSP or your new PSP Go? Do you want to spend thousand of dollars to find a new but a good games, movies, music, software, themes, and more? So you have some options here.

Best Way To Save Money And Get Your Favorite Games, Movies, Music, Software, Themes And More At The Same Time – PSP Go Download Center

By: Dimitar Mishev | 02/12/2009
Are you looking for a website that can allow you to download PSP or PSP Go games, movies, music and more? Are you paying $30 to $50 for each PSP Go game fro your local store? Do you want to stop doing that and pay one time fee and star download newest PSP Go games, movies, music and more? So here is your solution that will help you to stop throwing your money away but get unlimited downloads to your favorite PSP games, movies, music, software, themes and more with only paying a small fee.

Stop Throw Your Money For Each PSP Go Game But Get Unlimited Lifetime Membership. – PSP Go Download Center – Unlimited Downloads For Your PSP Go

By: Dimitar Mishev | 02/12/2009
Are you looking for a website about your PSP or your new PSP Go who will allow you unlimited download for music, movies, games, software, themes and more? Do you want to stop throw away your money for each PSP Go game which cost between $30 and $40 and get unlimited access on millions PSP music, movies, games, software, themes and more? So you will ask how u can do that. I can tell you that you are on the right place.

How To Download PSP or PSP Go Games Movies, Music, Software, Themes, And More – PSP Go Download Center – Best Way To Save Money

By: Dimitar Mishev | 02/12/2009
So you just got your new PSP and you want to download games, movies, music, even software or themes but you’re not sure what to do or where to go? You don’t want to spend a fortune to get your favorite music, movies or PSP games. Well this article will show you how download games to your PSP. What you should do? First you should apply for membership on PSP Go Download Center.

PSP Go Downloads Center - It Will Save Your Money - Get Unlimited Downloads For Your Favorite PSP Games, Movies, Music, Software, And Much More

By: Dimitar Mishev | 02/12/2009
Sony PSP is so popular with gamers, they can play games anywhere and anytime with their PSP. But PSP is a multipurpose piece of gadget; it is not just for games but you can also watch movies and TV shows, installing different software and themes. Watching movies is another cool feature of PSP that you can enjoy but investing on UMD movie disk is expensive same as buying a game form Sony and you have to pay for every single movie and every single game.

Discover How To Download Music, Movies, Games, Software, Themes On PSP - Saving Money With PSP Go Download Center Is Guaranteed

By: Dimitar Mishev | 02/12/2009
PSP is one of the must have gadgets, a handheld device that became so popular with gamers due to its flexibility. This is one of the most wanted devices today which is easy to use. PSP is not only limited for video games but it can also play music, videos, display photos, watch TV shows, getting software and you can surf the net too. It's a good thing that music can also be played on PSP which benefits a large percentage of people fond of listening music wherever they go.

Proven Tips and Tactics About the Newest Trend in Making Money Online

By: Etienne A. Gibbs, MSW | 12/11/2007 | Business
Despite the controversy about predators lurking on social networking sites, these sites are setting a new trend when it comes to making money online. One such site leading the pack is Yuwie. Similar to the others like MySpace, Facebook, FriendsWin, hi5, and Xianz, to name a few, Yuwie has the distinction of being the only one to pay its members for what they normally do for free on the other sites.

Proven Tips, Tools, and Tactics and Other Security Measures to Stay Safe Online (part 2 of 2)

By: Etienne A. Gibbs, MSW | 16/04/2007 | Business
Although the Internet basically provides a positive and productive experience, cyber-attacks against our personal privacy and security are reaching epidemic proportions. These attacks are occurring in our own homes and businesses. Our own computers are being used are being used as zombies to attack other people, businesses, and even our nation itself. As an average Internet user, you may not be aware of these threats.

Proven Tips, Tools, and Tactics and Other Security Measures to Stay Safe Online (part 1 of 2)

By: Etienne A. Gibbs, MSW | 14/04/2007 | Internet
Staying safe online is no longer a given, but a necessary extracurricular activity. Here are nine security measures you can employ immediate to protect yourself, your family, and your business. By following the recommended cyber security measures outlined here, you can limit the harm cyber criminals can do not only to your computer, but to everyone's computer.

What Everybody Ought to Know: It's No Longer Enough to Install Off-the-shelf Security Software

By: Etienne A. Gibbs, MSW | 10/04/2007 | Internet
The Internet-based attacks on your personal privacy and security continue to worsen year after year. The future of Internet security is gloomy ¬ and it takes an extremely dedicated and savvy computer user to find the right mix of security programs and stay current with the newest threats. Internet security is not a one-time event.

Is your College Student Carelessly Inviting Identity Thieves and Predators?

By: Etienne A. Gibbs, MSW | 28/03/2007 | Internet
And what are some of the careless acts of college students that leave them vulnerable to identity theft? Here are a few of the ways they might be inviting predators, hackers, and other cybercriminals:

Your Money and your Life: Gone in Sixty Seconds Flat!

By: Etienne A. Gibbs, MSW | 21/03/2007 | Technology
A new trend recently discovered: online hazards in hotels. Authorities are becoming alarmed at the number of traveler-victims who have reported that their personal or financial information was stolen after they had used a computer in a hotel's business center. It seems like the cybercriminals use keylogging software to record their victim's key strokes.

Criminals Flock to the Internet and to a Computer in your Home or Business

By: Etienne A. Gibbs, MSW | 20/03/2007 | Internet
Organized crime seems too be extremely active in the scam known as "phishing" in which they send emails under the guise of being a financial institution or other legitimate organization. In the email they ask unsuspecting victims to verify personal information such as account numbers and passwords.

Some Precautions: Identity Thieves Combine Offline and Online Options

By: Etienne A. Gibbs, MSW | 09/03/2007 | Internet
Two out of five identity theft victims surveyed by the Identity Theft Assistance Center (ITAC, a nonprofit organization dedicated to fighting identity theft through victim assistance, research and law enforcement partnerships) know how their personal data was stolen. This knowledge provides valuable insight about how identity theft occurs.

Submit Your Articles Free: Signup
Article Categories




Use of this web site constitutes acceptance of the Terms Of Use and Privacy Policy | User published content is licensed under a Creative Commons License.
Copyright © 2005-2008 Free Articles by ArticlesBase.com, All rights reserved. (0.13, 2, w1)