Google Removes Chrome Extension Used in Banking Fraud

  • 16 August 2017
  • 3 replies
  • 653 views

Userlevel 7
Badge +54
August 16, 2017  By Michael Mimoso
 


 
Google has removed from the Chrome Web Store a malicious browser extension used by criminals in Brazil to target corporate users with the aim of stealing banking credentials.
 
The twist is that the attackers did their homework on their targets, learning via social networks whom inside an organization was closely involved in making financial transactions. Those victims were then contacted over the phone by the criminals posing as bank employees who urged the victims to install an update to the bank’s security module, otherwise threatening them that they would lose access to their account.
 
Full Article.

3 replies

Userlevel 7
Badge +11
Once again another security situation that could have been avoided through minor education and communication. 
:( 
Userlevel 7
@ wrote:
Once again another security situation that could have been avoided through minor education and communication. 
:( 
It is laudable that they removed it...but IMHO "minor education and communication" have little to do with it. It would have been much better if Google had prevented this crapware from ever getting into the Extension Store in the first place...but they seem to be incapable of policing their own backyard...:@
Userlevel 7
Badge +11
@ wrote:
@ wrote:
Once again another security situation that could have been avoided through minor education and communication. 
:( 
It is laudable that they removed it...but IMHO "minor education and communication" have little to do with it. It would have been much better if Google had prevented this crapware from ever getting into the Extension Store in the first place...but they seem to be incapable of policing their own backyard...:@
Totally agree that google should have done something about it, but if I had some form of "notification" about works IT systems I would contact IT department just to be sure 🙂. But Google has a lot of work to do. :( 

Reply