Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Sophisticated "Emmental" campaign targets banking authentication

by The Gurus
October 14, 2020
in Editor's News
Share on FacebookShare on Twitter

A new campaign which targets banking websites and their users has been detected.

Named ”Operation Emmental”, the research by Trend Micro, the effort sees attackers targeting banks which use session tokens sent through SMS messages, a concept commonly used in Austria and Switzerland.

In the attack, if a user clicks on a malicious link or attachment, the malware changes the configuration of their computers then removes itself, having changed the computers’ DNS settings to point to a foreign server controlled by the cyber criminals. The malware installs a rogue SSL root certificate in their systems so that the malicious HTTPS servers are trusted by default and they see no security warning.

When a user with an infected computer tries to access the bank’s website, they are instead pointed to a malicious site that looks like that of their bank and once the user enters their credentials, they are instructed to install an app on their smartphone. This malicious Android app is disguised as a session token generator of the bank and intercepts SMS messages from the bank and forwards them to a command-and-control (C&C) server or to another mobile phone number.

This attack process sees the attacker not only gain the victims’ online banking credentials through the phishing website, but also the session tokens needed to bank online as well, meaning the criminals end up with full control of the victims’ bank accounts.

Chris Boyd, malware intelligence analyst at Malwarebytes, said: “Operation Emmental’s complexity highlights the high value that criminals place on active bank account information. The use of a piece of malware which removes itself once it has completed its primary objective, in addition to a piece of Android malware which is designed to intercept one time passwords from the bank itself, gives you a pretty sophisticated attack which is hard for the average online banking user to spot.

“One could argue that having such a complicated chain of events could work in a potential victim’s favour – if just one part of the multi-step heist fails, then the whole scheme could fall flat. Despite this, I think we will see more of this type of cross platform approach which blends social engineering, multiple platforms and sophisticated obfuscation.”

According to Trend Micro, the actors behind this attack have been active since 2011 and users in Switzerland, Austria, Sweden and Japan are targeted.

TK Keanini, CTO of Lancope, said that rather than a revolutionary way of attacking, this was more evolutionary. “This is the co-evolution of the defenders ra
ising the bar in one area, and the attackers having to modify their tactics to another,” he said. “This tiny configuration change represents a larger more known strategy by the attacker which is to get ‘in the middle’ of the communication.  This is just another way for them to place themselves in the middle where they can gain an advantageous position in the communication channels.”

Asked if the victim count could be high, Keanini said he felt most users would fall victim because targeting smartphones is relatively new, and most users consider them to be safe and secure. “Attackers will continue to try to every access vector to the smartphone because having a footprint on the smartphone has many advantages to their attack campaign,” he said. “Users need to get much more paranoid about downloads and the general security of their smartphone.

“This type of DNS attack is very difficult to detect without the right telemetry.  These traffic patterns are incredibly anomalous but the attackers know that no one is monitoring for this anomaly and thus getting away with it. This is the reason why it is so effective.

“If service providers or organisations monitored the DNS traffic and through anamoly detection algorthms detect that certain machines were not using the configured DNS servers, the attack could be detected at it on set no matter what country was being targeted.”

Michael Sutton, VP of security research at Zscaler, said: “We have seen that users are all too willing to install apps on smartphones without scrutinising requested permissions. This is especially the case for Android’s ‘all-or-none’ permission model where users cannot install an app unless all permissions are accepted up front.

“This differs from Apple’s model whereby an application can first be installed and individual permissions allowed or denied as they are needed, without impacting the overall application. It should also be noted that in this particular attack, because the Android application is using a legitimate permission – reading SMS messages – this application could just as easily be delivered from the official Google Play store as it isn’t exhibiting clearly malicious behaviour and is unlikely to be rejected during the approval process.

“Awareness is key in alerting users to the threat of an attack such as this, but unfortunately, users will remain the weak link in the security chain regardless of the attention that as attack receives. Google is in the best position to break this attack by restricting/preventing apps from accessing SMS content.”

Tags: AndroidAuthenticationBankMalware
ShareTweet
Previous Post

More flaws in Internet Explorer, but it is fastest to fix

Next Post

European Central Bank attacked with data for sale – industry views

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol