<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.0.4" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Money Mules: laundering out the phish smell</title>
	<link>http://www.phishtank.com/blog/2006/11/10/money-mules-laundering-out-the-phish-smell/</link>
	<description>A blog about and from PhishTank, a collaborative clearinghouse for data about phishing.</description>
	<pubDate>Thu, 21 Aug 2008 06:40:38 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.4</generator>

	<item>
		<title>by: mulehunter</title>
		<link>http://www.phishtank.com/blog/2006/11/10/money-mules-laundering-out-the-phish-smell/#comment-239</link>
		<pubDate>Thu, 16 Nov 2006 15:53:35 +0000</pubDate>
		<guid>http://www.phishtank.com/blog/2006/11/10/money-mules-laundering-out-the-phish-smell/#comment-239</guid>
					<description>I thought it might be worth providing a bit of extra background on the mule issue, as this is an issue familiar to the UK banking community for which I work. Mule recruitment is the other side of the phishing equation. Phishing is one process by which fraudsters get hold of bank account login credentials (malware being another). However, once the fraudsters have loggged into a victim's account, they need a way of getting away with the money, and this is not as straightforward as it sounds. Methods of achieving this vary around the world, depending upon the way banking systems are set up in various countries. In the UK the "money mule" is a common method - an individual duped into thinking they are working for a legitimate company by agreeing to use their bank account to move money around. In our experience the mule's account is not generally raided by the fraudsters, but they obviously do need to know enough about the mule's account to be able to move money into it. 

For takedown purposes, mule web sites pose some challenges when compared with phishing sites. The most obvious of these is that, wheras with a phishing site there is a clear abuse of a known bank's trademarks and other intellectual property, most mule sites are completely made up and could conceivably be for a real company which can make it difficult to convince a host to take down the site. In addition, some mule recruitment emails contain links to the sites of genuine companies (the recruiters want you to respond to them via an email which appears elsewhere on the email). These and other factors can make it a challenge from a liability and process view to deal with mule sites, which is undoubtedly the goal of the fraudsters.

Having said that, we would be very interested in supporting ways of automating the detection and removal of mule recruitment sites and email addresses.

Some further background and examples are available on our site: www.banksafeonline.org.uk</description>
		<content:encoded><![CDATA[<p>I thought it might be worth providing a bit of extra background on the mule issue, as this is an issue familiar to the UK banking community for which I work. Mule recruitment is the other side of the phishing equation. Phishing is one process by which fraudsters get hold of bank account login credentials (malware being another). However, once the fraudsters have loggged into a victim&#8217;s account, they need a way of getting away with the money, and this is not as straightforward as it sounds. Methods of achieving this vary around the world, depending upon the way banking systems are set up in various countries. In the UK the &#8220;money mule&#8221; is a common method - an individual duped into thinking they are working for a legitimate company by agreeing to use their bank account to move money around. In our experience the mule&#8217;s account is not generally raided by the fraudsters, but they obviously do need to know enough about the mule&#8217;s account to be able to move money into it. </p>
<p>For takedown purposes, mule web sites pose some challenges when compared with phishing sites. The most obvious of these is that, wheras with a phishing site there is a clear abuse of a known bank&#8217;s trademarks and other intellectual property, most mule sites are completely made up and could conceivably be for a real company which can make it difficult to convince a host to take down the site. In addition, some mule recruitment emails contain links to the sites of genuine companies (the recruiters want you to respond to them via an email which appears elsewhere on the email). These and other factors can make it a challenge from a liability and process view to deal with mule sites, which is undoubtedly the goal of the fraudsters.</p>
<p>Having said that, we would be very interested in supporting ways of automating the detection and removal of mule recruitment sites and email addresses.</p>
<p>Some further background and examples are available on our site: <a href='http://www.banksafeonline.org.uk' rel='nofollow'>www.banksafeonline.org.uk</a>
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: PW</title>
		<link>http://www.phishtank.com/blog/2006/11/10/money-mules-laundering-out-the-phish-smell/#comment-220</link>
		<pubDate>Tue, 14 Nov 2006 22:50:59 +0000</pubDate>
		<guid>http://www.phishtank.com/blog/2006/11/10/money-mules-laundering-out-the-phish-smell/#comment-220</guid>
					<description>A newbie here, so I may be missing the obvious and I see that there's a mule scam awaiting verification in the list - I'm certainly confused.

A mule scam is certainly criminal activity that ends up stinging the victim.
They generally try to pose as respectable businesses, often using names that are similar to established companies. 
They use spam email with links to deceptive websites.
Warning against these would provide a valuable service.

I know they probably occupy a grey area between a 'true' phish and a other scams but aren't we splitting hairs a bit if we say that this isn't a type of phishing?</description>
		<content:encoded><![CDATA[<p>A newbie here, so I may be missing the obvious and I see that there&#8217;s a mule scam awaiting verification in the list - I&#8217;m certainly confused.</p>
<p>A mule scam is certainly criminal activity that ends up stinging the victim.<br />
They generally try to pose as respectable businesses, often using names that are similar to established companies.<br />
They use spam email with links to deceptive websites.<br />
Warning against these would provide a valuable service.</p>
<p>I know they probably occupy a grey area between a &#8216;true&#8217; phish and a other scams but aren&#8217;t we splitting hairs a bit if we say that this isn&#8217;t a type of phishing?
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: MASA</title>
		<link>http://www.phishtank.com/blog/2006/11/10/money-mules-laundering-out-the-phish-smell/#comment-216</link>
		<pubDate>Tue, 14 Nov 2006 01:40:21 +0000</pubDate>
		<guid>http://www.phishtank.com/blog/2006/11/10/money-mules-laundering-out-the-phish-smell/#comment-216</guid>
					<description>From the blog post it seems like that a money mule is a phish technique</description>
		<content:encoded><![CDATA[<p>From the blog post it seems like that a money mule is a phish technique
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: astrogeek</title>
		<link>http://www.phishtank.com/blog/2006/11/10/money-mules-laundering-out-the-phish-smell/#comment-215</link>
		<pubDate>Mon, 13 Nov 2006 19:03:56 +0000</pubDate>
		<guid>http://www.phishtank.com/blog/2006/11/10/money-mules-laundering-out-the-phish-smell/#comment-215</guid>
					<description>Wouldn't a site like this eventually ask for your banking information, much like a straightforward phish we all know and love?  It sounds like a variation of the Nigerian scams.</description>
		<content:encoded><![CDATA[<p>Wouldn&#8217;t a site like this eventually ask for your banking information, much like a straightforward phish we all know and love?  It sounds like a variation of the Nigerian scams.
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
