Share

30 financial institutions scammed by phone apps

San Francisco - More than 30 financial institutions in six countries have been defrauded by sophisticated criminal software that convinces bank customers to install rogue smartphone programs, a major security company reported on Tuesday.

Though many of the elements of the malicious software, including the interception of one-time passwords sent to phones, have been used elsewhere, the latest criminal campaign is unusual in that it combines many different techniques and leaves few traces.

Researchers at Trend Micro, which dubbed the campaign Emmental after the Swiss cheese, said they were working with European police and major banks on the continent that were early victims.

Banks in Austria, Sweden, Switzerland and Japan have all been hit, with damages somewhere in the millions of dollars, said Trend Micro Chief Cyber security Officer Tom Kellermann.

Kellermann said that some of the attackers were in Romania but that the leader spoke Russian and could be based there.

Login details

The least sophisticated part of the gang's work so far appears to be in the delivery of the software, according to a report by Trend Micro researchers.

E-mails that appear to be from major retailers come with attachments that, when opened, prompt the user to download a malicious attachment of an unusual type, called a control panel item.

If users do not click again, they are safe. If they do, the software goes to work and hides itself out of view of most antivirus protection.

When an infected user later tries to visit the website of one of the targeted banks, the software redirects them to a fake site, which asks for login details and then prompts the user to download a smartphone app.

That app later intercepts the one-time passwords, giving the gang both that data as well as the login information, enough to clean out an account.

"This shows the continuing escalation, automation and blending of attacks," Kellermann said.
We live in a world where facts and fiction get blurred
Who we choose to trust can have a profound impact on our lives. Join thousands of devoted South Africans who look to News24 to bring them news they can trust every day. As we celebrate 25 years, become a News24 subscriber as we strive to keep you informed, inspired and empowered.
Join News24 today
heading
description
username
Show Comments ()
Rand - Dollar
18.98
+1.2%
Rand - Pound
23.76
+0.8%
Rand - Euro
20.36
+1.0%
Rand - Aus dollar
12.39
+0.8%
Rand - Yen
0.12
+1.4%
Platinum
915.50
+0.4%
Palladium
1,008.50
+0.4%
Gold
2,324.57
+0.4%
Silver
27.36
+0.7%
Brent Crude
88.02
-0.5%
Top 40
68,529
-0.1%
All Share
74,489
-0.0%
Resource 10
61,532
+1.8%
Industrial 25
103,048
-0.9%
Financial 15
15,871
+0.2%
All JSE data delayed by at least 15 minutes Iress logo
Company Snapshot
Editorial feedback and complaints

Contact the public editor with feedback for our journalists, complaints, queries or suggestions about articles on News24.

LEARN MORE
Government tenders

Find public sector tender opportunities in South Africa here.

Government tenders
This portal provides access to information on all tenders made by all public sector organisations in all spheres of government.
Browse tenders