home.social

#bank — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #bank, aggregated by home.social.

fetched live
  1. Чат в банковских приложениях приравняли к месседжерам
     
    Из открытых публикаций стало известно, что Т-Банк и Райффайзенбанк проиграли ФСБ суд по требованию установить СОРМ и обеспечить круглосуточный удалённый доступ к данным своих интернет-сервисов.
    ФСБ говорит, что Банк – не просто банк, а ещё и организатор распространения информации, потому что в приложении есть чат, где люди могут общаться между собой.
    А это значит, что приложение обеспечивает обмен сообщениями между пользователями.
    А это, в свою очередь, значит, что банк попадает под действие «Закона Яровой»: обязан хранить сведения о пользователях, факты обмена сообщениями и содержание.
    И, естественно, обеспечить доступ уполномоченным органам.

    Сначала банки отказались, сославшись на статью 26 закона «О банках и банковской деятельности» и статью 23 Конституции. Но суды встали на сторону ФСБ: раз это распространение информации, то и закон «Об информации» применим.

    #infosec #sorm #bank #russia

  2. What the Source Leak Says About HookBot

    ERMAC and HookBot are two branches of one Android banking trojan sold as a service, forking from shared code originating with Cerberus. A copy of the builder, Laravel backend, and React panel leaked in August 2025, enabling unrelated operators to deploy panels with default credentials and keys still in place. The lineage runs Cerberus to ERMAC to Hook, confirmed through source code analysis showing identical database migrations and network protocol structures. HookBot added VNC remote control and 38 new commands while maintaining ERMAC's core. The leaked source includes a Docker stack, Obfuscapk builder, and IP-whitelist firewall that hides panels but leaves the builder port exposed. Operators target 484 apps across 40+ countries including Japanese banks, Brazilian financial institutions, Turkish banks, and cryptocurrency wallets. Detection artifacts survive in builder obfuscator flags and favicons, while panel titles remain easily changed.

    Pulse ID: 6a8dc2ed12d6752a7f9e258d
    Pulse Link: otx.alienvault.com/pulse/6a8dc
    Pulse Author: AlienVault
    Created: 2026-08-25 16:29:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APK #Android #Bank #BankingTrojan #Brazil #Cerber #CyberSecurity #Docker #InfoSec #Japan #Mac #OTX #OpenThreatExchange #RAT #RCE #Trojan #Turkish #VNC #bot #cryptocurrency #AlienVault

  3. Fake security scans trick victims into uninstalling their antivirus

    A network of fraudulent websites branded as SysScan with Microsoft logos are conducting fake security scans to deceive victims into uninstalling legitimate antivirus software. Eleven sites hosted on a single server run convincing but fabricated security checks using basic browser data, deliberately constraining security scores between 13 and 30 out of 100 to guarantee failure. The scam falsely claims Windows no longer supports third-party antivirus and tricks victims into providing personal information, banking details, and remote-access credentials through a detailed form that transmits data directly to Telegram. After form submission, victims receive calls from supposed refund managers who exploit the removed security protections. The operation shows indicators of AI-generated code and targets both consumer and enterprise security software users.

    Pulse ID: 6a8d3fe1fad98d6499f15c73
    Pulse Link: otx.alienvault.com/pulse/6a8d3
    Pulse Author: AlienVault
    Created: 2026-08-25 07:10:25

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Bank #Browser #CyberSecurity #InfoSec #Microsoft #OTX #OpenThreatExchange #RAT #Telegram #Windows #bot #AlienVault

  4. @spheniscus

    Gerade weil das Bewusstsein dafür fehlt oder es vielen egal ist, erwarte ich von einem Europäischen Anbieter eine APP die den #Datenschutz beachtet.

    Sonst ist das eine Bankrott Erklärung gegenüber den Techkonzernen die den #Datenschutz mit Füßen treten.

    Auch hilft es nicht zu sagen die #Bank ist Schuld und man soll wechseln wenn man das nicht möchte.

    Viele können es nicht (Kredite etc)

    @LyrischerPoet @dalcacer @heiseonline

  5. @claudius

    Du bezahlst diese Kosten über den Händler wo Du kaufst.

    Und jetzt sollen alle zu deiner Bank wechseln?

    Da jede #Bank sein eigene Suppe kocht, ist Wero komplett intransparent.

    Eine reine zusätzliche Gelddruckmaschine für die #Bank

    Jede Überweisung tuts auch.

    @LyrischerPoet @dalcacer @heiseonline

  6. Blend between Banking Malware & Spyware

    Pulse ID: 6a87f27b0157cf27d412b42c
    Pulse Link: otx.alienvault.com/pulse/6a87f
    Pulse Author: Tr1sa111
    Created: 2026-08-21 06:38:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Bank #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #SpyWare #bot #Tr1sa111

  7. Blend between Banking Malware & Spyware

    Pulse ID: 6a87f27c4691e10e953ad42e
    Pulse Link: otx.alienvault.com/pulse/6a87f
    Pulse Author: Tr1sa111
    Created: 2026-08-21 06:38:52

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Bank #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #SpyWare #bot #Tr1sa111

  8. Blend between Banking Malware & Spyware

    A newly identified Android malware family named Manic combines banking malware and mobile spyware capabilities, targeting Ukrainian banks, government services, messaging applications, Russian and European financial institutions, and global fintech and cryptocurrency services. Active since February 2026, Manic enables extensive Device Takeover operations through sophisticated surveillance and remote-control features. It employs advanced PIN stealing techniques without requiring traditional overlay attacks, utilizing Accessibility services as a UI keylogger to capture lock-screen inputs, recovery phrases, and authentication codes. A distinctive feature is its Wi-Fi mesh egress technique, allowing compromised devices to relay stolen data through other infected phones via Wi-Fi Direct, Bluetooth, or BLE when direct C2 access is unavailable. The malware monitors 169 applications including banks, cryptocurrency wallets, government eID services, and military-focused messengers across multiple countries.

    Pulse ID: 6a86e8ec13b0f932cade0ec4
    Pulse Link: otx.alienvault.com/pulse/6a86e
    Pulse Author: AlienVault
    Created: 2026-08-20 11:45:48

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #Bank #CyberSecurity #Europe #Government #InfoSec #KeyLogger #Malware #Military #OTX #OpenThreatExchange #RAT #Russia #SpyWare #UK #Ukr #Ukrainian #bot #cryptocurrency #AlienVault

  9. Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign

    Grandoreiro, a notorious banking trojan active since 2016 across Latin America, continues operations despite major law enforcement disruption in 2024. Recent campaigns leverage DLL sideloading techniques, abusing the legitimate Duplicate Files Finder application to execute malicious code. The loader incorporates extensive anti-analysis mechanisms including sandbox detection, virtual machine artifact checks, process blacklisting, and environment profiling to evade automated analysis systems. These defensive checks occur before C2 contact, indicating high priority on avoiding detection. Telemetry from June 2026 shows activity concentrated in Latin America, primarily Mexico, with limited presence in Europe and North America. The malware uses custom string obfuscation combining proprietary decryption with Base64 encoding, and communicates with C2 infrastructure over TCP port 6432 using encrypted requests containing host-specific information.

    Pulse ID: 6a86146ca27454b03a4cbe2d
    Pulse Link: otx.alienvault.com/pulse/6a861
    Pulse Author: AlienVault
    Created: 2026-08-19 20:39:08

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Bank #BankingTrojan #Brazil #CyberSecurity #Europe #InfoSec #LatinAmerica #LawEnforcement #Mac #Malware #Mexico #NorthAmerica #OTX #OpenThreatExchange #RAT #RCE #SMS #SideLoading #TCP #Trojan #bot #AlienVault

  10. Balonx Sistema: The Face Behind the PhaaS Affecting Mexican Banking

    A sophisticated Phishing-as-a-Service platform called Balonx Sistema, operated from Mexico, targets over 20 financial institutions through tiered subscriptions. The platform employs real-time WebSocket session hijacking to defeat multi-factor authentication, distributing a Spyroid-based Android RAT via fake security alerts. Since October 2025, over 1,100 victims' credentials have been harvested. The operation includes CallFlow, an AI-driven vishing module using GPT-4o-mini, ElevenLabs synthetic voice, and OpenAI Whisper for automated telephone fraud, eliminating human operators. The platform uses continuous domain rotation across 350+ domains since 2019, maintains centralized PostgreSQL infrastructure, and is openly promoted through Facebook groups. The operator, identified as 'balonx', manages a sophisticated criminal enterprise generating approximately $99,000 USD through subscription-based access priced between 3,000-6,000 MXN weekly.

    Pulse ID: 6a85ce6194c0be6ceb256c93
    Pulse Link: otx.alienvault.com/pulse/6a85c
    Pulse Author: AlienVault
    Created: 2026-08-19 15:40:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #Bank #CyberSecurity #Facebook #InfoSec #Mexican #Mexico #OTX #OpenThreatExchange #Phishing #PostgreSQL #RAT #SQL #bot #AlienVault

  11. Hackers Use AI Voice Calls and Fake Banking Pages to Bypass MFA and Steal Accounts

    Indicators extracted from public reporting. Source: group-ib.com/blog/balonx-siste

    Pulse ID: 6a85c43554b382dba75c54b7
    Pulse Link: otx.alienvault.com/pulse/6a85c
    Pulse Author: CyberHunter_NL
    Created: 2026-08-19 14:56:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Bank #CyberSecurity #GroupIB #HTTP #HTTPS #InfoSec #MFA #Mexico #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  12. Octagon: A New Android Bot Targeting Crypto Wallets and Banking Apps

    Pulse ID: 6a85364d765b677a97b3910a
    Pulse Link: otx.alienvault.com/pulse/6a853
    Pulse Author: Tr1sa111
    Created: 2026-08-19 04:51:25

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #Bank #CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #Tr1sa111

  13. Octagon: A New Android Bot Targeting Crypto Wallets and Banking Apps

    In June 2026, a previously undocumented Android fraud bot called Octagon was identified, sold as malware-as-a-service by Russian-speaking actor AndroidKitKat for $1,400 monthly. The malware employs accessibility overlays, hidden VNC, SMS interception, unlock-pattern capture, and balance reading capabilities to target cryptocurrency wallets, exchanges, and banking applications. Distributed through sideloaded APKs with Restricted Settings bypass, Octagon connects infected devices to a Windows command-and-control panel where operators monitor applications, read screens, and control devices remotely. The malware maintains persistence through multiple mechanisms while appearing benign to security scans. Three APK samples were recovered, including deployments using Lifted Dreams game and Bahrain government lures. The malware captures credentials through HTML WebView overlays targeting Trust Wallet, Binance, MEXC, MetaMask, and messaging apps like Telegram and WhatsApp, enabling cryptocurrency theft and account t...

    Pulse ID: 6a8474eb4f130dfa41887e40
    Pulse Link: otx.alienvault.com/pulse/6a847
    Pulse Author: AlienVault
    Created: 2026-08-18 15:06:19

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APK #Android #Bank #Binance #CyberSecurity #Government #HTML #InfoSec #Malware #MalwareAsAService #OTX #OpenThreatExchange #RAT #RCE #Russia #Rust #SMS #Telegram #VNC #WhatsApp #Windows #bot #cryptocurrency #AlienVault

  14. Fraudulent Employment Operations

    Multiple clusters of North Korean IT workers, designated as PurpleDelta, have been identified applying to over 1,100 companies between late 2024 and early 2025, primarily targeting software, technology, staffing, consulting, and healthcare sectors. The operators maintained at least 22 fabricated personas supported by AI-generated profile photos, custom ChatGPT assistants, and fraudulent identity documents. They demonstrated sophisticated tradecraft, applying to up to 60 positions daily using multi-account management browsers and detailed tracking spreadsheets. During interviews, operators employed screen recording software and AI transcription tools to generate real-time answers, often repeating ChatGPT responses verbatim. Once employed at ten or more organizations, they recorded internal meetings, used personal devices and bank accounts, and coordinated via Telegram and Slack with facilitators who maintained company-issued hardware. This activity represents an ongoing insider threat to organizations hirin...

    Pulse ID: 6a8478fdbb5ebd2c1549a543
    Pulse Link: otx.alienvault.com/pulse/6a847
    Pulse Author: AlienVault
    Created: 2026-08-18 15:23:41

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Bank #Browser #ChatGPT #CyberSecurity #Healthcare #InfoSec #Korea #NorthKorea #OTX #OpenThreatExchange #RAT #Telegram #bot #AlienVault

  15. @alloalli

    Ja, dass nennt sich #Quishing

    Darum gings aber nicht sondern wie weit QR Codes für Banküberweisungen schon verbreitet sind

    Zudem hat der Händler \ Gastronomie kein Interesse daran dir einen falschen QR Code zukommen zu lassen

    Bei #Wero wird das der nächste Schritt sein um auch den Stationären Handel Wero anbieten zu können

    Nur das die #Bank dabei doppelt kassieren kann

    Über die Transaktionskosten für Wero und deine normalen Gebühren für dein Bankkonto

    @dalcacer @heiseonline

  16. Octagon Can Steal SMS One-Time Codes During Banking and Crypto Account Takeovers

    Indicators extracted from public reporting. Source: iverify.io/blog/octagon-androi

    Pulse ID: 6a846480fa0bec6e91d2788a
    Pulse Link: otx.alienvault.com/pulse/6a846
    Pulse Author: CyberHunter_NL
    Created: 2026-08-18 13:56:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #Bank #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SMS #bot #CyberHunter_NL

  17. “…the US Office of the Comptroller of the #Currency, whose leader #Trump appointed, approved a preliminary charter for World Liberty Financial (WLF) to become a #bank.

    The charter would permit WLF to issue USD1, a #stablecoin tied to the dollar, and to manage and hold assets for customers and settle payments faster.

    WLF is the cryptocurrency venture launched by the Trump family and their close allies the #Witkoff family.”

    reuters.com/world/us-regulator

  18. @strelitzer

    Aso, ich soll also jetzt vorher nachfragen welche #Bank scannt oder nicht bevor ich meine Daten jemanden anderem gebe......

    @dalcacer @heiseonline