Online Threat Alerts (OTA)
An anti-cybercrime community alerting the public.

Sberbank Online Users under attack from mTAN SMS Trojan

Sberbank, a bank in Russian, online customers are under attack by hackers and scammers who are using a fake malicious Sberbank mobile phone application called "SberSafe" with Trojans "Spy.AndroidOS.Citmo" and "Spy.Win32.Carberp.ugu" to capture mTAN authorization code in SMS messages, in order to steal money from a victim’s bank account using online banking. mTAN stands for Mobile Transaction Authentication Number and is used by some banks to authorize financial transactions online.

Advertisements

After a banking customer completes a financial transaction online, a SMS or a Text Message is sent to the customer’s mobile phone with the mTAN code. The customer must enter this code in their online banking account before the transaction can be processed.

Even if a hacker or a scammer is able to steal your online banking username and password, they will not be able to process any financial transactions from your online banking account, unless they are able to get hold of the mTAN code for that transaction. The mTAN code is unique per transaction, therefore, will be different for every banking transaction and randomly chosen by the bank.

The users of Sberbank Online are sent a link to download the fake and malicious Sberbank mobile application called “SberSafe”. If the user launches this malicious application, it will capture any SMS text messages with mTAN codes in it and send it to the criminals behind this application. They will use this to authorize financial transactions in the victim’s online backing account.  All of this is done without the victim knowing because the Trojan hides the incoming SMS text messages it needs from the victim and send it silently to the criminals.

This malicious application was available for download at Google Play but was removed after it was reported to them by Kaspersky Lab. Google tries hard to prevent malicious applications from entering their store and is one of the safest places to download mobile applications.

Sberbank Online recommends that their customers do the following:

Check the comment section for additional information, or share what you know or ask a question about this article, by clicking the 'View or Write Comment' button below.

Note: Some of the information in samples on this website may have been impersonated or spoofed.

Share this article with others.
Advertisements
Write / View Comments (0)
View on Online Threat Alerts (OTA)
Help Maintain Online Threat Alerts (OTA)