跳到主体内容

Kaspersky Lab Assists in Russia’s Largest Cybercriminal Arrest: The Hackers Who Stole $45 Million

2016年6月2日

Kaspersky Lab experts and Sberbank, one of Russia’s largest banks, worked closely with Russian Law Enforcement Agencies in an investigation into the Lurk gang that has now resulted in the arrest of 50 people

Kaspersky Lab experts and Sberbank, one of Russia’s largest banks, worked closely with Russian Law Enforcement Agencies in an investigation into the Lurk gang that has now resulted in the arrest of 50 people. Those detained are suspected of involvement in the creation of infected computers networks that resulted in the theft of more than 45 million dollars (3 billion rubles1) from banks, other financial institutions and businesses since 2011.  This is the largest ever arrest of hackers to have taken place in Russia.

In 2011, Kaspersky Lab detected the activity of an organized cybercriminal gang using the Lurk Trojan - a sophisticated, universal and multi-modular malware with wide functionality - to gain access to victims’ computers. In particular, the gang was looking for a way into remote banking services so that it could steal money from customer accounts.

“From the very start, Kaspersky Lab experts were involved in the law enforcement investigation into Lurk.  We realized early on that Lurk was a group of Russian hackers that presented a serious threat to organizations and users. Lurk started attacking banks one-and-a-half years ago; before then its malicious program targeted various enterprise and consumer systems.

“Our company’s experts analyzed the malicious software and identified the hacker’s network of computers and servers. Armed with that knowledge the Russian Police could identify suspects and gather evidence of the crimes that had been committed. We look forward to helping to bring more cybercriminals to justice,” - said Ruslan Stoyanov, Head of computer incidents investigation at Kaspersky Lab.

During the arrest the Russian police managed to prevent the transmission of fake money transactions worth more than 30 million dollars (2,273 billion rubles2).

The Lurk Trojan

In order to propagate the malware, the Lurk group infected a range of legitimate websites with exploits, including leading media and news sites. A victim simply had to visit a compromised webpage to become infected with the Lurk Trojan. Once inside the victim’s PC, the malware would start to download additional malicious modules that enabled it to steal the victim’s money.

Media websites were not the only non-financial target of the group. In order to hide their traces behind VPN-connection, the criminals also hacked into various IT and telecom companies, using their servers to remain anonymous.

The Lurk Trojan is distinctive in that its malicious code is not stored on the victims’ computer but in the random access memory (RAM). Also, its developers tried to make it as difficult as possible for anti-virus solutions to detect the Trojan. So they made use of different VPN-services, the anonymous Tor network, compromised Wi-Fi connection points and servers belonging to the attacked IT organizations.

We urge companies to pay close attention to their security measures and to regularly perform an IT infrastructure security check, so that at the very least they are protected from known vulnerabilities. It is also extremely important to teach employees the basics of responsible cyber-behavior.

In addition, a company needs to introduce measures that will enable it to detect an on-going targeted attack. The best strategy here is to complement the approach to threat prevention with significant investment in threat detection and response. Even the most sophisticated targeted attacks can be spotted by their abnormal activity when compared to regular business workflow.

Kaspersky Lab detects the Lurk Trojan as Trojan.Win32.Lurk, Trojan-Banker.Win32.Lurk, Trojan-Spy.Win32.Lurk.


1data from the Ministry of Internal Affairs in Russia
2data from the Ministry of Internal Affairs in Russia

Kaspersky Lab Assists in Russia’s Largest Cybercriminal Arrest: The Hackers Who Stole $45 Million

Kaspersky Lab experts and Sberbank, one of Russia’s largest banks, worked closely with Russian Law Enforcement Agencies in an investigation into the Lurk gang that has now resulted in the arrest of 50 people
Kaspersky logo

关于卡巴斯基

卡巴斯基是一家成立于1997年的全球网络安全和数字隐私公司。卡巴斯基不断将深度威胁情报和安全技术转化成创新的安全解决方案和服务,为全球的企业、关键基础设施、政府和消费者提供安全保护。公司提供全面的安全产品组合,包括领先的端点保护解决方案以及多种针对性的安全解决方案和服务,以及用于应对复杂和不断变化的数字威胁的网络免疫解决方案。全球有超过4亿用户使用卡巴斯基技术保护自己,我们还帮助全球200,000家企业客户保护最重要的东西。要了解更多详情,请访问www.kaspersky.com.cn.

相关文章 企业新闻