iBanking is back in Poland
ID: 9bdf4af8-5ab2-5ec7-b8d0-5694d26ed28d
STIX ID: report--9bdf4af8-5ab2-5ec7-b8d0-5694d26ed28d
Feed Name: CERT Polska
The report documents the iBanking campaign where compromised desktop machines inject JavaScript into e-banking sites to display a fake mobile security app prompt and deliver a malicious Android application via QR code or SMS; when installed the app steals one-time SMS passwords and gives attackers full control of the phone (call redirection, microphone eavesdropping, factory reset). It warns users to install apps only from trusted sources, avoid enabling installations from untrusted sources, and contact their bank if they see suspicious requests for OTPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
