Underground calling service helps cybercriminals extract sensitive info

Identity thieves use professional calling services to obtain missing pieces of information about victims

Researchers from security vendor Trusteer have come across a professional calling service that caters to cybercriminals. The business offers to extract sensitive information needed for bank fraud and identity theft from individuals.

The security company spotted an advertisement for making on-demand calls in English and other European languages to private individuals, banks, shops, post offices and similar organizations. At a cost of US$10 per call, cybercriminals were offered the possibility of obtaining the missing pieces of information they needed to pull off attacks.

Fraudsters can either use malware to steal personal and financial information or buy it from the underground market in bulk, said Amit Klein, Trusteer's chief technology officer. However, sometimes this information is insufficient to perform fraud, he added.

Cybercriminals are commonly faced with this problem because a large number of financial institutions have implemented advanced anti-fraud mechanisms. For example, many banks require one-time-use passwords (OTPs) to authenticate customers on their websites. Others require unique codes sent to mobile devices (mTANs) to authorize transactions.

One of the easiest ways to obtain information from a target is social engineering -- convincing someone to provide it. However, not every cybercriminal is skilled in such techniques and those who are capable of pulling off these attacks are often faced with a language barrier.

This is where call services like the one found by Trusteer come in. Their staff is trained to impersonate bank employees, computer technicians, travel agents, recruiters and other people to whom targeted individuals are likely to disclose information.

The callers receive background information about the targets from cybercriminals and use it to establish trusting relationships with the victims.

For example, if a fraudster wants to log into an account by using stolen online banking credentials, but is prompted for an OTP because he uses a different IP address than the real account holder, he can give a caller the information needed to impersonate a bank employee.

Armed with things like the victim's name, account number, birth date and other personal information, the caller can claim that he's performing system checks and ask the targeted individual to read back the code sent to their phone.

Illegal call services are not new. In September 2010, a 26-year-old Belarusian man named Dmitry M. Naskovets was extradited to the U.S. to face charges related to operating CallService.biz, a service that allowed cybercriminals to bypass phone verification checks enforced by U.S. banks. However, the number of rogue call centers has increased in recent years.

This year security companies reported cold-calling campaigns throughout the U.K., Canada, U.S., Australia and other countries, in which the callers impersonated computer technicians from ISPs (Internet service providers) or Microsoft to trick people into installing malware on their computers. Some of the schemes were tracked back to India, where because of low-cost labor, these businesses are very profitable.

In this case the advertisement was seen on a Russian forum, so there is a high probability that the service is managed by Russian-speaking individuals. "In addition, since the service is available during American and European working hours, it might indicate that the group is operating in these regions," said Trusteer security researcher Ayelet Heyman.

According to Heyman, the service is still operational at this time and Trusteer is not aware of any types of actions taken to shut it down. There is also a possibility that the people behind it are routing the calls through compromised phone systems in order to decrease the costs of the operation, she said.

Users should treat all unsolicited calls with caution, regardless of what kind of information the person on the other end of the line has about them, Klein advised. They should also confirm any suspicious requests with the organization the caller is claiming to represent, but they should do so by calling its publicly listed numbers, not those provided by the caller.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags Trusteersecurity

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Lucian Constantin

IDG News Service
Show Comments

Cool Tech

Breitling Superocean Heritage Chronographe 44

Learn more >

SanDisk MicroSDXC™ for Nintendo® Switch™

Learn more >

Toys for Boys

Family Friendly

Panasonic 4K UHD Blu-Ray Player and Full HD Recorder with Netflix - UBT1GL-K

Learn more >

Stocking Stuffer

Razer DeathAdder Expert Ergonomic Gaming Mouse

Learn more >

Christmas Gift Guide

Click for more ›

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Walid Mikhael

Brother QL-820NWB Professional Label Printer

It’s easy to set up, it’s compact and quiet when printing and to top if off, the print quality is excellent. This is hands down the best printer I’ve used for printing labels.

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

David Coyle

Brother PocketJet PJ-773 A4 Portable Thermal Printer

I rate the printer as a 5 out of 5 stars as it has been able to fit seamlessly into my busy and mobile lifestyle.

Featured Content

Product Launch Showcase

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?