logo

iBanking is back in Poland

ID: 9bdf4af8-5ab2-5ec7-b8d0-5694d26ed28d

STIX ID: report--9bdf4af8-5ab2-5ec7-b8d0-5694d26ed28d

Feed Name: CERT Polska

Threat Score
70/100

Date Published: 2015-01-16

Date Updated: 2026-04-19

Author: CERT Polska

...
...

The report documents the iBanking campaign where compromised desktop machines inject JavaScript into e-banking sites to display a fake mobile security app prompt and deliver a malicious Android application via QR code or SMS; when installed the app steals one-time SMS passwords and gives attackers full control of the phone (call redirection, microphone eavesdropping, factory reset). It warns users to install apps only from trusted sources, avoid enabling installations from untrusted sources, and contact their bank if they see suspicious requests for OTPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.