Advisor
Wiki Threats & Attacks Malware Banking Trojans

Banking Trojans

1 min read
Jump to:

Summary

Banking Trojans are malicious software designed to steal sensitive financial information, such as online banking credentials and payment data, by infiltrating user devices. They often operate by intercepting communications, logging keystrokes, or manipulating web sessions to facilitate unauthorized access to banking accounts and financial services.

Key Characteristics

  • Targets online banking and financial applications to capture login credentials.
  • Employs techniques like keylogging, form grabbing, and web injection to steal data.
  • Often delivered via phishing emails, malicious downloads, or exploit kits.
  • Can evade detection through obfuscation, encryption, and polymorphic code.
  • May use man-in-the-browser attacks to manipulate transactions in real-time.
  • Frequently communicates with command-and-control servers to exfiltrate data.

Defensive Controls

  • Implement multi-factor authentication (MFA) to reduce credential theft impact.
  • Use updated antivirus and anti-malware solutions with behavioral detection.
  • Deploy web filtering and email security to block phishing and malicious links.
  • Educate users on recognizing phishing attempts and safe browsing habits.
  • Apply least privilege principles and monitor for unusual account activity.
  • Keep operating systems and applications patched against known vulnerabilities.

Related Security Solutions

Endpoint detection and response (EDR) platforms, secure web gateways, email security solutions, multi-factor authentication systems, and network intrusion detection systems (NIDS) are commonly employed to detect, prevent, and respond to banking Trojan threats.

Tags: Application Attacks Banking Trojans Cybersecurity endpoint detection and response keylogging malware multi-factor authentication Phishing Threats & Attacks web injection