By all accounts, security is one of the main obstacles toward widespread adoption of cloud computing. In the latest example of financial malware targeting enterprises, cloud providers are being targeted by the Zeus Trojan by capturing a screenshot of payroll services web page with a corporate users whose machine is infected with the Trojan visits this website. This allows Zeus to steal the user ID, password, company number and the icon selected by the user for the image-based authentication system.
These attacks are designed to route funds to criminals, and bypass industrial strength security controls maintained by larger businesses, according to Amit Klein, CTO of web security company Trusteer.
The financial losses associated with a Zeus attack can be significant. Last August, cybercriminals reportedly funneled $217,000 from the Metropolitan Entertainment & Convention Authority (MECA). According to published reports, an employee at MECA was victimized by a phishing e-mail and infected with malware that stole access credentials to the organization’s payroll system.
“The more interesting issue here is who’s being targeted ... payroll cloud services,” said Oren Kedem, director of product marketing for Trusteer. Kedem says this could allow cybercriminals to add phony employees to the payroll – namely money mules – and transfer them payment from the victimized business.
Because of the nature of payroll systems, Trusteer expects to see increased cybercriminal activity using this type of fraud scheme for the following reasons:
“A better alternative for protecting sensitive cloud payroll, treasury, and other financial applications is to prevent malware from getting onto the endpoint in the first place,” Klein said in a blog post. “This requires a layered approach to security that looks for specific crime logic footprints, not signatures, to prevent malware on an infected machine from stealing login credentials.”