Skip to main content

Trusteer uncovers new method used to infiltrate online banks

posted onMarch 13, 2012
by l33tdawg

Boston-based Web security firm Trusteer has uncovered a new scheme to raid online banking accounts. In this newly discovered method, the bad guys steal the mobile device SIM details during an online transaction, get the existing SIM canceled and replaced with a new one.

Here's how it works: thieves use the Gozi trojan to steal IMEI numbers from bank account holders when they login to their online banking application. As the bank uses an OTP system to authorize transactions, when they've got the IMEI number, attackers call the service provider, report the device missing or stolen and ask for a new SIM card. With the newly obtained SIM, all OTP transactions intended for the victim's phone will be sent to the attacker instead. More details will be posted on the Trusteer blog this Thursday. 

Source

Tags

Industry News Security Hackers

You May Also Like

Recent News

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th