Banks warn of account number swapping virus

Latest collection of data for analysis and insights.
Post Reply
shukla7789
Posts: 1142
Joined: Tue Dec 24, 2024 4:29 am

Banks warn of account number swapping virus

Post by shukla7789 »

A wave of malware notifications has recently swept through the news and news systems of Polish banks. The information concerns a virus that replaces users' bank account numbers. The situation occurs when manually entering the recipient's account number from the keyboard. The malware replaces the entered string of 26 digits with its own account number. We are talking about the new VBKlip 2.0 virus, called Banatrix by specialists.

How to protect yourself against the virus?
account number changing virus
freeimages.com

You can protect yourself from pests and criminals trying to steal money in this way. The first and most important stage of verification is to check the correctness of the entered bank account number before confirming the transfer order. Banatrix automatically changes the entered account number to its own. Some banks require confirmation of the transfer using a one-time el salvador whatsapp database password, e.g. mBank does this, described in the entry mBank opinions about the account . In such a case, we still have the possibility of verifying the account number in the SMS message. In the case of banks using a token to authorize transactions, a double system of checking the account number is not possible to use.

Antivirus software - update signatures
The next important step is primarily preventive measures. I mean antivirus software installed on the user's computer. Its presence alone is not enough. It is necessary to regularly update not so much the program itself, but primarily the virus signature database. As CERT states on its website, most antivirus software currently correctly detects and removes the virus.
It is worth knowing that just checking the checksum of the infected DLL file - widndow.sys (without the above actions) will not allow VBKlip 2.0 to be detected. Because it is encrypted with a different key each time during saving.
Post Reply