Tag Archive for: Banking

DSL modem hack used to infect millions with banking fraud malware

An administration panel of one vulnerable DSL modem.

Millions of Internet users in Brazil have fallen victim to a sustained attack that exploited vulnerabilities in DSL modems, forcing people visiting sites such as Google or Facebook to reach imposter sites that installed malicious software and stole online banking credentials, a security researcher said.

The attack, described late last week during a presentation at the Virus Bulletin conference in Dallas, infected more than 4.5 million DSL modems, said Kaspersky Lab Expert Fabio Assolini, citing statistics provided by Brazil’s Computer Emergency Response Team. The CSRF (cross-site request forgery) vulnerability allowed attackers to use a simple script to steal passwords required to remotely log in to and control the devices. The attackers then configured the modems to use malicious domain name system servers that caused users trying to visit popular websites to instead connect to booby-trapped imposter sites.

“This is the description of an attack happening in Brazil since 2011 using 1 firmware vulnerability, 2 malicious scripts and 40 malicious DNS servers, which affected 6 hardware manufacturers, resulting in millions of Brazilian internet users falling victim to a sustained and silent mass attack on DSL modems,” Assolini wrote in a blog post published on Monday morning. “This enabled the attack to reach network devices belonging to millions of individual and business users, spreading malware and engineering malicious redirects over the course of several months.”

Read 8 remaining paragraphs | Comments


Ars Technica » Technology Lab

Fake Android Antivirus App Likely Linked to Zeus Banking Trojan … – PCWorld

Fake Android Antivirus App Likely Linked to Zeus Banking Trojan
PCWorld
A recently discovered fake Android security application is most likely a mobile component of the Zeus banking malware, security researchers from antivirus firm

“android security” – read more

MAKING SENSE OF IT ALL: What should be the main 2012 trend? Mobile Security – ABA Banking Journal

MAKING SENSE OF IT ALL: What should be the main 2012 trend? Mobile Security
ABA Banking Journal
By John Ginovsky With all the predictions of what's coming for 2012 floating around, one really should stand out: Increased mobile security. For example, it is extremely rare when any politician goes out on a limb, so it's important to take note when

and more »

“mobile security” – read more

Banking by smartphone can be risky – San Jose Mercury News

“Most instances of banking fraud are not due to the bank’s technology being compromised, but to people unwittingly giving out their personal information to criminals via phishing scams and copycat sites, or their computers being infected with malware …
Read more