SecurityInfoWatch, click to go home
Most Popular: Today | OverallMost E-Mailed: Today | Overall

No quick fix to Chinese bank virus, security experts warn

China orders banks to step up online security measures in wake of cyber thefts
SOUTH CHINA MORNING POST
via NewsEdge Corporation
Updated: 07-16-2009 5:10 pm

The warning follows an order by the Monetary Authority on Monday demanding that banks step up online banking security after three clients, from two banks, lost HK$289,000 between April and June from unauthorised online transactions. Eight banks have reported being targeted.

The customers who lost money were believed to have accessed their online banking accounts using personal computers infected with Trojan horse programs that record keystrokes and send the information to a hacker. The hacker then logged in to the account using the stolen usernames and passwords.

A one-time password - generated by a security device given by the bank or sent as a text message - to authenticate transactions was also intercepted in the same manner and enabled hackers to transfer the money.

Roy Ko Wai-tak, manager of the Computer Emergency Response Team Co-ordination Centre, said the attacks were most likely launched by organised cyber criminals targeting specific bank clients.

He said the technique had "conceptually and practically" compromised the double authentication process used by banks.

"The logistics - from planting the Trojans to wiring out the money - are very complicated and require expert skills," he said, adding that the hackers would frequently alter the Trojan programs to avoid being blocked by anti-virus software.

Chow Kam-pui, associate director of the Centre for Information Security and Cryptography at the University of Hong Kong, said the Trojan programs were normally hidden in the attachments of spam e-mails.

Post a Comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.
CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
Image CAPTCHA
Copy the characters (respecting upper/lower case) from the image.

there is a remedy for such attacks

IDentiWall eBanking provides end-to-end e-Banking security even if the customer's computer is contaminated with malwares and viruses.
From the description this attack looks like regular man-in-the-browser attack that IDentiWall fights daily…