In February 2019, Kaspersky Lab discovered the shadow online store Genesis, which sells more than 60,000 stolen digital personalities worth from $ 5 to $ 200, including logins and passwords to online stores and payment services. With this data, attackers can easily deceive means to combat online fraud, penetrate into the accounts of real users and conduct transactions that do not cause suspicion of the bank without hacking.
Usually, when a customer enters the data required for an online transaction, the system not only checks their correctness, but also compares them with a unique digital profile to make sure that they are dealing with the real owner. Depending on whether the data matches, the transaction is approved, canceled or sent for further analysis. A digital identity is not only a digital trace that a person leaves on devices and browsers used by him to make payments (data about the screen and operating system; time zone; headers that the browser sends to the server; installed plugins; window size, etc.), but and data collected based on advanced analytics and machine learning algorithms, including cookies and digital user habits.
Digital identity can be stolen, and also created from scratch with the help of special tools. A study by Kaspersky Lab has shown that attackers are already actively using these methods to bypass solutions for protection against financial fraud. The company's experts found not only the underground online store Genesis, but also the Tenebris browser with a built-in digital trace generator. Using the latter, the attackers reproduce the user's network activity in the browser and on the proxy server, and then use the stolen login and password to log into his account and conduct online operations on his behalf.
“We see that there are more and more cases of fraud with someone else’s payment cards. Financial institutions are actively investing in funds to combat them, but it is not easy to determine that a digital profile has been stolen and used by hackers. To stop the spread of this threat, it is necessary to eliminate such black markets. That is why we urge law enforcement agencies around the world to pay special attention to this problem and join the fight against it, ”said Sergey Lozhkin, senior antivirus expert at Kaspersky Lab.
As a measure to combat financial fraud, Kaspersky Lab recommends that companies:
- conduct multi-factor authentication at each stage of identity verification;
- introduce additional tools to verify identity, for example, check biometric data;
- use the most advanced analytical tools to study user behavior;
- supplement the SIEM solution and other security control systems with constantly updated threat data streams in order to gain access to the most up to date information about cyber risks and be ready for possible attacks.
You can learn more about this threat on the following site.