Zeus-based Ice IX Trojan Redirects Bank Phone Calls To Attackers

A new variant of the Zeus financial malware platform that targets online banking customers in the UK and US has been identified by computer security firm Trusteer.

Ice IX steals bank account information and telephone account details, which enables the attacker to divert calls from a bank to a controlled phone number.

Fraudulent process

“We believe the fraudsters are executing fraudulent transactions using the stolen credentials and redirecting the bank’s post-transaction verification phone calls to professional criminal caller services that approve the transactions,” said Adam Klein, CTO of Trusteer.

In an attack, the malware captures the victim’s login details, secret question and answer, and account balance. Telephone account details are then stolen via a web injection which requests the person’s telephone numbers (including work and mobile) and phone service provider. Trusteer noted in one attack that Ice IX presented the three most popular phone service providers in the UK (TalkTalk, BT and Sky) within the data form to obtain the information.

The final part of the attack captures a victim’s telephone account number, something which is necessary to change phone service settings and forward calls on to the attackers as phone companies use the number to verify a customer’s identity. By claiming there has been “a malfunction of the bank’s anti-fraud system with its landline phone service provider” the fraudster is able to justify the request as part of the verification process.

“Fraudsters are increasingly turning to these post-transaction attack methods to hide fraudulent activity from the victim and block email and phone communication from the bank,” said Klein. “This allows attackers to circumvent security mechanisms that look for anomalies once transactions have already been executed by the user.”

Jiten Karia

Recent Posts

Apple, Google Mobile Ecosystems Should Be Investigated, CMA Told

CMA receives 'provisional recommendation' from independent inquiry that Apple,Google mobile ecosystem needs investigation

2 hours ago

Australia Rejects Elon Musk Claim About Social Media Ban For Under-16s

Government minister flatly rejects Elon Musk's “unsurprising” allegation that Australian government seeks control of Internet…

5 hours ago

Northvolt Files For Bankruptcy Protection In US

Northvolt files for Chapter 11 bankruptcy protection in the United States, and CEO and co-founder…

7 hours ago

UK’s CMA Readies Cloud Sector “Behavioural” Remedies – Report

Targetting AWS, Microsoft? British competition regulator soon to announce “behavioural” remedies for cloud sector

22 hours ago

Former Policy Boss At X, Nick Pickles, Joins Sam Altman Venture

Move to Elon Musk rival. Former senior executive at X joins Sam Altman's venture formerly…

1 day ago

Bitcoin Rises Above $96,000 Amid Trump Optimism

Bitcoin price rises towards $100,000, amid investor optimism of friendlier US regulatory landscape under Donald…

1 day ago