Banking Malware

Written by Mark Wilshaw Cyber Security Services Manager and Information Security Manager at SYTECH.

The trend of malware threats towards banking has changed over the last 15-20 years.  In the early 2000’s, when online banking started to be implemented, up until around 2020, the most common method used by attackers was a technique known as Man-in-the-Browser (MitB).  This technique evolved over the years but always relied on exploiting vulnerabilities in internet browsers to intercept or steal data within the browser. Initially, this was as simple as logging keystrokes to capture user input in the browser (as seen in malware such as Zeus or SpyEye). This was later superseded by malware capable of manipulating the data being sent from an internet browser to divert funds into alternative accounts; One of the most impactful examples of this type of malware in the UK was Shylock. This was particularly effective as the malware would infect a computer and then propagate to other users via communication methods used on that device (ie. email, chat, Zoom etc).  Messages appearing to come from a trusted contact would make a user more likely to click the malicious links and infect their own device.

More modern malware has evolved beyond these techniques. Malware developers are increasingly making their software modular, meaning that the initial infection will not always perform a malicious action itself, but will later download different modules depending on the attacker’s goal.  For instance, the malware may first deploy a trojan designed to steal data, such as usernames, passwords or banking information.  Once this data has been taken, additional modules may be downloaded to encrypt data as part of a ransomware attack.  This approach allows attackers to cast a wide net and launch attacks based on the context of the device and environment they infect.

Artificial intelligence is also changing the threat landscape. AI is now widely used by cybercriminals to generate phishing campaigns, making fraudulent emails, text messages, and even phone calls far more convincing than they previously have been. In the past, phishing attempts often contained poor grammar, spelling mistakes or other tell-tale signs that helped users to identify them however, those signs are now eroding with the use of AI.

AI is also creating new opportunities for hackers in less obvious ways. While AI assistants and platforms have become a popular alternative to traditional search engines, they are known to occasionally ‘hallucinate’ information by presenting incorrect answers with confidence. Attackers are exploiting this behaviour by creating malicious websites that correspond with these fabricated locations or web addresses. For example, a user asking an AI assistant how to access their bank’s online services could be directed to an incorrect website that has been created by cybercriminals however, as the recommendation appears to come from a trusted AI source, users may be less likely to verify the legitimacy of the site before entering sensitive information.

Banks in the UK are obliged to use robust security measures as enforced by the Financial Conduct Authority (FCA).  These measures include using Multi-Factor Authentication (MFA), monitoring transactions and the use of anti-fraud technologies to identify suspicious activity.  Most banks also provide guidance to their customers on the use of Anti-Virus software, specifically endorsing a preferred solution.  Whilst banking institutions have their own guidelines and provide advice, they cannot ensure the security of the device a customer uses to interact with their banking services.  A large portion of cybersecurity measures in business involve user education and usage policies.  A business, such as a bank, cannot force its customers to adhere to best practice, so this is where the weakness will present itself for an attacker.

A user can follow the advice below to take positive steps towards protecting themselves:

·         Use Multi-Factor Authentication (MFA) – Where possible, users should enable MFA.  This is not limited to banking accounts as the theft of accounts such as email addresses can lead to other avenues of attack.

·         Be Aware of Phishing Attempts – Suspicious emails or messages should be ignored, especially those purporting to be from a bank.  If any links are prompting to enter personal information then be especially wary.

·         Keep Devices Up-to-Date – Make sure that if your device is prompting for software updates then these are allowed to be done.  Updated software will provide the best protection against vulnerabilities that are exploited by malware.

·         Use Anti-Malware Software – The use of Anti-Malware software adds a layer of security to a device for if other protection methods above fail.

·         Avoid Insecure Connections – Avoid using public WiFi when making financial transactions as these connections are often less secure.