Homegrown Banking Solutions The Best Defense?

image

By Ray Birch

SAN DIEGO—Credit unions with homegrown home banking solutions may be at lower risk—for now—from the new GozNym Trojan, which reportedly has CUs in its crosshairs.

But analysts are emphasizing that all financial institutions need to dramatically step up their member/customer education to alert account holders of the new risk, which can leave the consumer confident they are dealing with their financial institution when they are not.

Experts caution that the reach of GozNym, which is suspected to be targeting more mainstream home banking solutions from large providers, will eventually spread its reach. The only real defenses, analysts insist, are strong employee and member education and behavioral analytics.

The new hybrid GozNym Trojan managed to steal $4 million from financial institutions in just two weeks after it was first discovered last month. Two powerful pieces of Trojan malware, Nymaim and Gozi ISFB, have been combined to create the hybrid GozNym.

Active Attack

GozNym is currently engaged in an active campaign with 72% of targets, including business banking institutions, being credit unions and retail banks, IBM X-Force reported. Business banking (28%) and CUs (27%) are the biggest targets, according to IBM X-Force.

The extremely stealthy Trojan combines the best of both Nymaim and Gozi ISFB to create a very problematic threat, analysts have stated.

stickleyJim

Jim Stickley

The reason financial institutions with home banking solutions developed in-house may not be a target now is because GozNym is suspected to taking aim at the big fish—FIs that operate on home banking solutions from large companies that are widely used.

“Malware, like GozNym, is created to go after the masses,” said Jim Stickley, CEO of Stickley on Security. “So if you are using the XYZ online banking app and 200 other credit unions are doing the same, it is in the hacker’s best interest to go after this solution, because he knows there is a large pool of credit unions to attack.”

On the other hand, said Stickley, if the credit union wrote its own home banking solution it is likely safter, unless the crook is targeting an FI for some specific reason, or if the institution has billions in assets.

Targets Changing

But that does not mean the situation won’t change tomorrow, Stickley said.

“All of these Trojans are designed to modify the payload and continually evolve,” he said. “Once they launch and begin having success, crooks add additional payloads and increase the number of organizations they target. If you are not on the GozNym list today, don’t take a deep breath and feel that you are OK.”

The big problem for banks and credit unions, and not just from GozNym, is that automated attacks are getting much more sophisticated. Stickley said GozNym is particularly crafty.

“It is doing what is called a man in the middle attack, infecting the web browser itself,” explained Stickley. “Your browser gets infected, and you won’t know it. Then you go to XYZ credit union and you know it is a legitimate site—it says ‘https’ in the browser and the CU’s domain name is there. So you feel confident you are truly where you are supposed to be, and you are.”

However, because the user’s browser has been compromised, the browser won’t perform exactly as it should, said Stickley.

“You are at the legitimate credit union site, and then the malware can pop up a form or a message on the fly,” said Stickley.

“The message may say that the credit union needs you to update some information. It looks like it is part of the main site, part of the page, so you are very apt to believe it and update your social security number, provide your mother’s maiden name . . .,” explained Stickley.

Behavioral Analytics

Stickley, along with Luis Rojas, senior director of product management for Guardian Analytics in Mountain View, Calif., agree that behavioral analytics is a strong line of defense.

“We have seen over and over again, with threats like this, relying on endpoint protection to keep the Trojan out of the system is not enough,” said Rojas. “That effort is like putting an iron front door on your home but leaving the back door open. There are so many vectors from which this threat can enter.”

Rojas reminded that behavioral analytics is about defending once someone gets through your door.

“Behavioral analytics lets you learn what a legitimate user looks like and to know a member’s online behavior intimately, so whenever there is a shift from normal behavior you can react,” Rojas said.

Behavioral analytics also detect when someone is not logging in from their customary location, and is trying to perform, for example, a wire transfer, said Stickley.

“You can then flag those anomalies and stop the transaction,” Stickley said.

Savvy Crooks

But crooks are even getting better at fooling FIs about the origin of the fraudulent transaction.

“For example, if I am attacking a person and I am stealing credentials, I can trace the IP address where they were,” said Stickley. “Then, when I am trying to steal from the user’s credit union account, I can try to find a similar location that I can bounce off of so I look like I am coming from the same place as the account holder.”

Stickley added that it is much harder to apply behavioral analytics to business accounts, as transactions vary to a much greater degree compared to consumer accounts.

RojasLuis

Luis Rojas

Rojas and Stickley emphasized member education, such as telling people to avoid untrusted sites and phishing attacks. Stickley stressed, too, that consumers should know that they must update programs like Adobe Flash and Java with the security patches those programs offer almost on a monthly basis. He said if that is not done, hackers can infect a PC just by the person visiting a site, and not even clicking on anything. Even ads on trusted sites—ads that have been compromised by fraudsters—can infect a computer without being clicked on if a user does not keep up with security patches.

“At the end of the day, if people don’t fall victim to begin with . . .,” said Stickley.

Member Education

He insisted that banks and credit unions need to dramatically step up their member/customer education to alert account holders about specific attacks that are in place and emerging, and what to do to defend against them. But Stickley is not sure FIs want to do this.

“For whatever reason, financial institutions seem to not want to talk about these risks because it might scare people,” said Stickley. “At this point that is just silly. The risks are there, people are already scared—when they hear about cyber threats it is generally from news outlets and the stories are typically doom and gloom. At this point if a financial institution is not informing account holders about all the threats, they are doing their customers and members a disservice.”

CUToday.info asked NCUA whether any credit unions could be identified that had been attacked by GozNym, and the agency responded, “NCUA will continue to monitor the situation and trends jointly with our fellow financial regulators and federal agency partners, and take appropriate action where necessary. “

Section: Standard
Word Count: 1500
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto.flux5.ccplatform.net/THE-feature/Homegrown-Banking-Solutions-The-Best-Defense