The captured men were accused of using Zeus trojan features to hack into customer accounts, stealing money by transferring it to other accounts created by accomplices, eventually sending it to mastermind through Western Union.
But ' litchi can't cover the holy eye ', the traces that they carelessly left behind helped the experts follow. BitDefender found command servers and controlled the use of criminals. According to experts BitDefender revealed, once investigators track command servers and control, they can track transactions to the server and find traces of criminals and hidden conspirators. really behind the incident.
These aggressive attacks show that banks need to take careful and strong measures to protect customers' safety. BitDefender experts have instructed how to fight trojans specializing in stealing bank accounts, especially Trojan Zeus:
1. Strictly control how customers change their e-mails and phone numbers in bank records. Allowing to change information online too easily will enable attackers to send and receive information from banks more simply and conveniently. BitDefender recommends: only allow these changes by going directly to bank branches.
2 . Send a notice of any changes in your bank account. BitDefender recommends: If any account information is changed, the notice must be sent to both the email address and the SMS message, so that the customer can promptly respond to any unauthorized changes.
3 . Notify when there is a new update on the list of people who can receive a transfer from a customer's account. If an attacker controls an account, he can steal money through online banking easily. BitDefender recommends: notification via e-mail and SMS to customers when the transfer list is updated.
4. Allow time for customers to read and respond to the notice. If a customer is unable to read e-mail or SMS within a certain period of time, attackers can transfer money to new beneficiaries under their control before the account holder is legally have the opportunity to detect frauds. BitDefender recommends: Do not transfer money to new beneficiaries within seven days after they have been identified.