Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Sophisticated malware detected that steals online banking passwords, thwarts text authentication
The Courier Mail, Australia ^ | March 9, 2016 8:57pm | Nick Whigham

Posted on 03/11/2016 1:49:25 PM PST by Swordmaker


Android users could be vulnerable to a sophisticated new banking malware. NEW malware that targets mobile banking apps of Australia’s big banks has been detected.

The sophisticated virus infects Android users and can steal password details and even thwart two-factor authentication.

In a concerning discovery for mobile bankers, the malware was discovered by ESET security systems and works by presenting victims with a fake version of the login screen when they access their legitimate banking application.

When customers login they are unwittingly met with the fake page to input their passwords. Creators of the malware are then able to steal these details and access the account remotely to transfer money out.

Customers of Commonwealth Bank, Westpac, ANZ and the National Australia Bank are all vulnerable to the malware which can hide on a person’s device until they use the banking app.

In addition to stealing the login details of customers, thieves can also intercept verification text messages sent to the device, allowing them to thwart extra security measures put in place by the banks.

“This allows SMS-based two-factor authentication of fraudulent transactions to be bypassed, without raising the suspicions of the device’s owner,” ESET malware researcher Lukas Stefanko said in a statement.

The malware is believed to have been developed in recent years from more primitive versions, to get to its current level of sophistication. The malware is reportedly designed so it can target multiple banks in Australia, New Zealand and Turkey.

“The attack has been massive and it can be easily refocused to any other set of target banks,” Mr Stefanko said.

BankWest, Bendigo Bank, St George Bank, Bank of New Zealand, Wells Fargo and Kiwibank are also among the list of vulnerable banks.

According to ESET, the Trojan spreads as an imitation of the Flash Player video application either installed from an infected website or via a predatory text message. Once it has been installed on the phone, the bogus app requests device administrator rights. If granted by the user, the malware then checks to see if any target banking applications are installed on the device. It then receives the fake login screens for each banking app on the phone, which will appear the next time the user logs in.

Cyber security expert Matthew Warren said the malware comes as no surprise.

“It’s an ongoing problem with android devices, because of the open source nature of the platform... There’s been a number of malware aimed at banking apps,” he told news.com.au.

Unlike Apple, for instance, which only allows users to download apps from its controlled App Store, Android users can download apps from anywhere.

Malware attacks such as this latest one are known as “spearfishing attacks” and “are an extension of the weakness of the android platform,” Mr warren said.

He said Android users should ensure they have malware protection software installed on their device if they’re using banking apps

HOW TO REMOVE IT FROM YOUR PHONE

For those who believe they are infected by the malware, they can remove it from the device by first decommissioning administrator rights for the app by going to Settings > Security > Device administrators > Flash Player > Deactivate.

From there, users can uninstall the malware app in settings.


TOPICS: Business/Economy; Computers/Internet
KEYWORDS:

1 posted on 03/11/2016 1:49:25 PM PST by Swordmaker
[ Post Reply | Private Reply | View Replies]

To: Swordmaker
I never do any financial transactions on my phone. I don't trust it.

I do all my financial transactions on a PC booting from a live Linux CD/USB.

2 posted on 03/11/2016 1:55:20 PM PST by E. Pluribus Unum ("If voting made any difference they wouldn't let us do it." --Samuel Clemens)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ThunderSleeps; dayglored; ~Kim4VRWC's~; 1234; Abundy; Action-America; acoulterfan; AFreeBird; ...
Android trojan Malware that steals bank passwords found circulating in Australia, masquerades as FLASH Video Player or can come in as a message. The malware can spoof two-factor protection. For you Apple users who use Android phones, beware. — PING!


Android Security
Ping!

Ping to Thundersleeps and dayglored for your lists to alert your lists to be on the lookout for this.

The latest Apple/Mac/iOS Pings can be found by searching Keyword "ApplePingList" on FreeRepublic's Search.

If you want on or off the Mac Ping List, Freepmail me

3 posted on 03/11/2016 1:56:07 PM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue..)
[ Post Reply | Private Reply | To 1 | View Replies]

To: E. Pluribus Unum
I do all my financial transactions on a PC booting from a live Linux CD/USB.

I go to the bank for mine!

4 posted on 03/11/2016 1:57:51 PM PST by JimRed (Is it 1776 yet? TERM LIMITS, now and forever! Build the Wall, NOW!)
[ Post Reply | Private Reply | To 2 | View Replies]

If you use an older Android device, with a pre-Android 5 os, then here's another you should be very concerned about:

Devastating Vulnerability Affects 66 Percent of Android Phones

5 posted on 03/11/2016 2:05:10 PM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue..)
[ Post Reply | Private Reply | To 3 | View Replies]

To: JimRed

I’m talking about Amazon and eBay and anything else that involves a credit card.


6 posted on 03/11/2016 2:21:22 PM PST by E. Pluribus Unum ("If voting made any difference they wouldn't let us do it." --Samuel Clemens)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Swordmaker

Its Android. I would not get Android unless its a Google Nexus Android phone. Google provides timely updates. The other manufacturers, not so much.


7 posted on 03/11/2016 3:06:04 PM PST by bkopto
[ Post Reply | Private Reply | To 1 | View Replies]

To: E. Pluribus Unum
I’m talking about Amazon and eBay and anything else that involves a credit card.

That would be the Missus. She does that all the time. I go to the store.

8 posted on 03/11/2016 3:19:50 PM PST by JimRed (Is it 1776 yet? TERM LIMITS, now and forever! Build the Wall, NOW!)
[ Post Reply | Private Reply | To 6 | View Replies]

To: bkopto
Its Android. I would not get Android unless its a Google Nexus Android phone. Google provides timely updates. The other manufacturers, not so much.

Some other makers also make it fairly easy to upgrade the Android OS.

9 posted on 03/11/2016 3:21:59 PM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue..)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Swordmaker

The Blackberry Android phone, called PRIV, may be the most secure Android phone.

http://blogs.blackberry.com/2016/03/beating-expectations-android-security-patching-for-priv/


10 posted on 03/11/2016 3:42:21 PM PST by deks
[ Post Reply | Private Reply | To 9 | View Replies]

To: deks

Black Phone 2 might be another alternative, though it is more for data privacy, it may have good protection from malware as well.

http://www.engadget.com/2015/09/28/blackphone-2-on-sale-north-america/


11 posted on 03/11/2016 4:12:42 PM PST by Sergio (An object at rest cannot be stopped! - The Evil Midnight Bomber What Bombs at Midnight)
[ Post Reply | Private Reply | To 10 | View Replies]

To: Swordmaker

I refuse to bank online. Problem solved.


12 posted on 03/11/2016 4:16:51 PM PST by vladimir998 (Apparently I'm still living in your head rent free. At least now it isn't empty.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: 109ACS; aimhigh; bajabaja; Bikkuri; Bobalu; Bookwoman; Bullish; Carpe Cerevisi; DarthDilbert; ...
A word of caution to any Freepers down under - ANDROID PING!

Android Ping!
If you want on or off the Android Ping List, Freepmail me.

13 posted on 03/12/2016 5:12:35 AM PST by ThunderSleeps (Stop obarma now! Stop the hussein - insane agenda!)
[ Post Reply | Private Reply | To 3 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson