This tool may make it easier for thieves to empty bank accounts

FraudFox is designed to spoof a browser fingerprint, an advanced method for tracking users

An application sold on the Evolution underground market makes it easier and faster to spoof a browser fingerprint, potentially fooling security systems.

An application sold on the Evolution underground market makes it easier and faster to spoof a browser fingerprint, potentially fooling security systems.

Banks and payment services are in a constant fight to detect account fraud, employing sophisticated ways to detect abnormal activities. One of those ways is "fingerprinting" a Web browser, or analyzing its relatively unique software stamp.

Web browsers relay a variety of data to websites, including a computer's OS, its time zone, language preference and version numbers for software plugins. When those parameters change, along with others such as an IP address, it may mean an account is being fraudulently accessed.

To prevent being locked out of an account, fraudsters can use a variety of methods to appear legitimate when browsing by using virtual machines and special browser plugins. But an enterprising developer has developed a software package that makes spoofing a browser fingerprint much easier.

Called FraudFox VM, the software is a special version of Windows with a heavily modified version of the Firefox browser that runs on VMware's Workstation for Windows or VMware Fusion on OSX. It's for sale on Evolution, the successor to the Silk Road online contraband market, for 1.8 bitcoins, which is about $US390.

It has been under development for a number of weeks by an Evolution vendor going by the nickname "hugochavez," whose avatar is a photo of the former Venezuelan president. The developer appear to have a good reputation, according to comments on an Evolution forum.

What FraudFox aims to do is make it faster and easier to change a browser's fingerprint to one that matches that of the victim whose account they're going to exploit, or simply mix up their own digital crumbs when browsing. It's not a new tool per se, and more advanced cybercriminals may already know the techniques, but FraudFox consolidates the functions.

FraudFox's effectiveness may depend on what service it is used against. Browser fingerprinting is just one metric used to detect fraudsters, said Ken Westin, senior technical marketing manager and security analyst with computer security company Tripwire, via email.

It's unclear how FraudFox would deal with detection of a person's IP address, as security systems also watch for use of proxy services such as Tor. "It will be interesting to see the tool when it is available and to test against existing fraud detection tools," he wrote.

FraudFox's control panel has drop-down boxes to select an OS version, whether that OS is 32- or 64-bit, the language, time zone and screen resolution. Another menu allows the selection of the fonts installed, another metric that can be tracked. A browser can be selected, as well as its version number and what version of Adobe System's Flash plugin is running.

The variety of options and the speed at which an attacker can change their fingerprint means that it likely will "be very useful for e-commerce and online banking fraud specifically," said Andrew Komarov, CEO of IntelCrawler, a Los Angeles-based security company.

A forthcoming feature for FraudFox will be a "profile generator script." That script is designed for use with a phishing page. If a victim can be lured to the page, the script will automatically collect the person's browser fingerprint. Those details are wrapped into a ".fox" file, which can then be used to quickly configure FraudFox.

One trial user of FraudFox who claims to have tested it praised it. The reviewer wrote that FraudFox helped increase the percentage of cards he was able to authorize through payment processors using Verified by Visa and MasterCard SecureCode, two security mechanisms used for online card-not-present transactions.

"I am very happy with this product and I am willing to purchase this real soon," wrote the person, nicknamed "Coin".

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags TripwireIntelCrawler

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jeremy Kirk

IDG News Service
Show Comments

Cool Tech

Bang and Olufsen Beosound Stage - Dolby Atmos Soundbar

Learn more >

Toys for Boys

Sony WF-1000XM3 Wireless Noise Cancelling Headphones

Learn more >

Nakamichi Delta 100 3-Way Hi Fi Speaker System

Learn more >

ASUS ROG, ACRONYM partner for Special Edition Zephyrus G14

Learn more >

Family Friendly

Philips Sonicare Diamond Clean 9000 Toothbrush

Learn more >

Mario Kart Live: Home Circuit for Nintendo Switch

Learn more >

Stocking Stuffer

Teac 7 inch Swivel Screen Portable DVD Player

Learn more >

SunnyBunny Snowflakes 20 LED Solar Powered Fairy String

Learn more >

Christmas Gift Guide

Click for more ›

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Tom Pope

Dynabook Portégé X30L-G

Ultimately this laptop has achieved everything I would hope for in a laptop for work, while fitting that into a form factor and weight that is remarkable.

Tom Sellers

MSI P65

This smart laptop was enjoyable to use and great to work on – creating content was super simple.

Lolita Wang

MSI GT76

It really doesn’t get more “gaming laptop” than this.

Jack Jeffries

MSI GS75

As the Maserati or BMW of laptops, it would fit perfectly in the hands of a professional needing firepower under the hood, sophistication and class on the surface, and gaming prowess (sports mode if you will) in between.

Taylor Carr

MSI PS63

The MSI PS63 is an amazing laptop and I would definitely consider buying one in the future.

Christopher Low

Brother RJ-4230B

This small mobile printer is exactly what I need for invoicing and other jobs such as sending fellow tradesman details or step-by-step instructions that I can easily print off from my phone or the Web.

Featured Content

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?