How Brazilian Steal Billions
Man-in-the-middle attack against a Brazilian payment system:
Brazil has an extremely active and talented cybercrime
underground, and increasingly Brazilian organized crime gangs are
setting their sights on boleto users who bank online. This is typically
done through malware that lies in wait until the user of the hacked PC
visits their bank’s site and fills out the account information for the
recipient of a boleto transaction. In this scenario, the unwitting
victim submits the transfer for payment and the malware modifies the
request by substituting a recipient account that the attackers control.
This is the sort of attack that bypasses any two-factor
authentication system, since it occurs after all authentication has
happened. A defense would be to send a confirmation notice to another
device the account-owner owns, confirming the details of the
transaction.
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.