Silence banking Trojan highlights password weakness

General News

Summary

The Silence banking Trojan that has hit at least 10 financial institutions has once again highlighted the weakness of using username and password combinations to access accounts.The latest banking Trojan to hit financial institutions has perfected the email lure and has extensive monitoring capabilities, but could be defeated using better user authentication, some have suggested.The Silence Trojan, discovered and named by researchers at security firm Kaspersky Lab, is described as an evolution of the campaign against financial institutions by the Carbanak gang, linked to the theft of $1bn from banks around the world .The next victim receives a phishing message from the address of a real person who works at the bank, which greatly increases the likelihood of a malicious attachment being clicked.Financial institutions could render employee and customer account credentials useless to attackers by using techniques such as passive biometrics and behavioural analysis, said Ryan Wilk, vice president at NuData Security.

Classifications

industries
Fintech & Banking
applications
Accounting and Taxes

AskAI Classifications

Labels
SaaS Cloud Computing Enterprise Software

Linked Companies

Microsoft
$1B+