Trojan targets UK online banks
Trojan targets UK online banks
R E L A T E D   C O N T E N T
ADVERTISEMENT

Trojan mugs UK web banking customers

Banker-AJ Trojan sends passwords and screenshots to remote hackers

Robert Jaques, vnunet.com 11 Nov 2004
ADVERTISEMENT

Security experts have issued a red alert over a previously undocumented Trojan designed to help criminals break into the accounts of UK internet banking customers.

The Banker-AJ Trojan (Troj/Banker-AJ) targets users of online banks including Abbey, Barclays, Egg, HSBC, Lloyds TSB, Nationwide and NatWest, according to security firm Sophos.

Banker-AJ has been coded to lie dormant in the background on infected Windows PCs, waiting for users to visit legitimate online banking websites.

Once the user visits one of a number of banking websites the malicious code is triggered into action, capturing passwords and taking screenshots.

This information is then relayed to remote hackers who can use it to break into the bank accounts of innocent users and steal money, Sophos warned.

The security firm has already reported similar techniques being used by criminals to break into Brazilian online bank accounts, but points to growing evidence of the same trick being attempted against UK financial institutions.

Graham Cluley, senior technology consultant at Sophos, said the Trojan was "like having a mugger looking over your shoulder as you type in your Pin number".

"People are increasingly aware of the threat from phishing emails which direct innocent users to fake banking websites in order to capture personal details. But this Trojan is different - it waits until the user visits a real banking website and then surreptitiously monitors the log-in process," he said.

More information about the Banker-AJ Trojan can be found here.

See also:

Online fraud set to soarEnhanced credit and debit card security bad news for e-businesses  26 Nov 2004
Increasing automation and sophisticationAnti-Phishing Working Group reports 'disturbing' new trend  24 Nov 2004
Five banks hit every dayFraudsters looking forward to a very merry Christmas  23 Nov 2004
Email masquerades as official software updateBank suspend elements of its online service to protect customers  17 Nov 2004
AVG Anti-Virus software clientMajor upgrade of popular free client released  11 Nov 2004
Internet content spoofing scamISA Server 2000 and Proxy Server 2.0 affected by internet spoofing scam  10 Nov 2004
New phishing techniqueJust open an email and you could be the next victim, warns security firm  04 Nov 2004
PhishingSurvey shows nine out of 10 financial web sites contain security flaws  27 Sep 2004
SecurityThe latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.  15 Apr 2004

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
Senior C# Agile Web Developer, Online Gaming, London My Client provides adult customers with high quality gambling and gaming services in an environment that is convenient, entertaining, fair, regulated and secure. My Client is one ... more >
| Aston Carter
EMC, NetApps, West London, Media • NetApps FAS ... more >
| Abraxas
Data Analyst / MI Analyst – Leading Online Gaming Company A Data Analyst / Trafficker is sought by a leading online gaming company. The role encompasses all aspects of online advertising including data handling, communicating ... more >
| JAM Recruitment
Field Applications Engineer Power Electronics/Supplies Europe/Based Surrey Permanent Position £35-45k Basic+Bonus 10-15%+Car/Car allowance A global organisation involved with the design and development of power supplies actively requires a Field Applications Engineer to strengthen it existing ... more >
More job opportunities