Subscribe

Fraudsters target JPMorgan clients

By Reuters
Boston/ New York, 22 Aug 2014

Fraudsters are targeting JPMorgan Chase customers in an e-mail "phishing" campaign that is unusual because it attempts to collect credentials for that bank and also infect PCs with a virus that steals passwords from other institutions.

The "Smash and Grab" campaign was launched on Tuesday with a widely distributed e-mail that urged recipients to click to view a secure message from JPMorgan, according to security researchers with corporate e-mail provider Proofpoint.

JPMorgan, the number one US bank by assets, confirmed that spammers had launched a phishing campaign targeting its customers.

"It looks like they sent it out to lots of people in hopes that some of them might be JPMorgan Chase customers," said bank spokeswoman Trish Wexler.

She said the bank believes most of the spam was stopped by filters at large Internet providers, adding the e-mail looked realistic because the attackers apparently used a screen grab from an authentic e-mail sent by the bank.

Users who click on a malicious link are asked to enter credentials for accessing accounts with JPMorgan. Even if they did not comply, the site attempts to automatically install the Dyre banking Trojan on their PCs, according to Proofpoint.

Dyre is a recently discovered piece of malware that seeks credentials from customers of Bank of America, Citigroup and the Royal Bank of Scotland Group, according to e-mail security firm Phishme.

Proofpoint VP of threat research Mike Horn says it is unusual for spammers to infect PCs with malware while trying to persuade users to provide banking credentials because that increases the odds of detection.

"Usually when they do credential phishing, that is all they do. In this case, they are throwing in the kitchen sink," Horn says.

Proofpoint saw about 150 000 e-mails from the group on Tuesday, the first day it noticed the campaign among its customers in the Fortune 500 and higher education.

That makes it a moderately large campaign, but the largest attempts involve sending more than one million pieces of spam over a few days to Proofpoint clients, he says. The firm manages over 100 million e-mail accounts.

Horn adds that Proofpoint quickly identified the spam and was able to stop it from infecting its customers, but was not sure how effective it was at infecting others.

Horn says his firm was unsure who was behind the e-mails, although much of the campaign's infrastructure was in Russia and Ukraine, and the group's tactics were consistent with those of Eastern European cyber crime gangs.

An FBI spokesman said he had no immediate comment.

A spokesman for the US Federal Trade Commission (FTC), the key federal agency charged with fighting spam, declined to comment.

"Since FTC investigations are non-public, I can't confirm or deny whether we are looking into this issue," said agency spokesman Jay Mayfield.

Share