Online security providers are warning credit unions and banks of a new scam that piggybacks onto digital certificates to gain access to the personal account information of online banking users.
The scammers are notifying online banking customers that their digital certificates have expired and directing the users to load a new certificate by clicking on an enclosed link. The link downloads the Prg Banking Trojan, which allows the hacker to piggyback on an online banking session without using the victim’s username or password.
Digital certificates are used specifically to block unauthorized access to online accounts.
According to SecureWorks, which discovered the malware, hackers have been using the digital certificate plot since last September. The hackers have successfully stolen more than $6 million from online banking customers in the U.S., Britain, Spain and Italy since then.
“This scheme is extremely clever and quite ironic considering that digital certificates are provided by financial institutions to protect online bank users from fraud,” said Don Jackson, senior security researcher with SecureWorks’ Counter Threat Unit.
Credit Union Journal