Beware: Hackers Pose as Bank Reps and Use Live Chat While Draining Accounts
- Posted on February 29, 2012 at 10:34pm by
Liz Klimas
- Print »
- Email »
What’s disturbing about a new hack of banking accounts – mostly those for commercial and business — isn’t its ability to drain the accounts dry, it’s that it uses information you willingly supply as it chats with you, according to Trusteer.

(Image: Trusteer)
Trusteer, a firm focused on enterprise and consumer desktop security, describes how, in working with a financial institution, it revealed a new type of malware that uses live chat in order to commit the fraud. It’s an act Trusteer calls “speaking with the devil.” Trusteer explains that it uses a malware platform called Shylock that freezes a banking session when the users logs on, alerting them that “security checks” are underway. Here’s what happens next:
The following message is displayed in the victim’s browser:
The system couldn’t identify your PC
You will be contacted by a representative of bank to confirm your personality.
Please pass the process of additional verification otherwise your account will be locked.
Sorry for any inconvenience, we are carrying about security of our clients.
It gets even stranger in the next step when the hacker begins live chatting with the victim, posing as a bank representative, to glean more personal information. Trusteer reports that the fraud could happen simultaneously to the live chat “enticing the victim to sign/verify fraudulent transactions that Shylock is initiating in the background.”
Trusteer calls this “yet another example of the ingenuity of fraudsters” using applications that trusted providers have instituted to help customers.
[H/T Gizmodo]



















Submitting your tip... please wait!
conservredneck
Posted on March 2, 2012 at 3:54pmto those that do online banking. If you didn’t initiate the conversation…don’t respond!!!
Report Post »BassChick
Posted on March 1, 2012 at 9:24am“my PC”? Maybe I’m using a Mac
Report Post »BSdetector
Posted on March 1, 2012 at 7:17amMisspellings and bad English are always a dead giveaway of fraud by foreigners.
“You will be contacted by a representative OF BANK to confirm your personality.”
Report Post »“Sorry for any inconvenience, we are CARRYING ABOUT SECURITY of our clients.”
Dennis McMurtrey
Posted on March 4, 2012 at 7:29amI caught hat too … might as well said
Report Post »“All your cash are belong to us”
Micmac
Posted on February 29, 2012 at 11:57pmWhy I do no financial transactions on line. except with 1 debt card with a small deposit in its account and will not clear if over the limit. No problems here.
NoBama 2012
Report Post »aquablue
Posted on February 29, 2012 at 11:01pm‘you will be contacted by a representative of bank to confirm your personality.’
Report Post »red alert warning!
it’s a chat session that harbors the shylock malware? wow.
Darmok and Jalad at Tanagra
Posted on February 29, 2012 at 10:58pmThey aren’t hackers, they are IRS agents. Healthcare costs money, and Obama needs a billion to keep his $290k job.
Report Post »Xyskalla
Posted on March 1, 2012 at 10:25amAnd his monthly vacations.
Report Post »dirtydog1776
Posted on March 1, 2012 at 5:45pmAnd to bail his dysfunctional family members out of jail.
Report Post »Razorhunters
Posted on February 29, 2012 at 10:44pmooops..?
oooh sheet…?
or haha…?
Report Post »you decide.