Pharming attacks are used by fraudsters to divert users from their online banking website to a fraudulent site. While phishing attacks lure in victims through social engineering tactics, such as a fake email from a bank, pharming attacks target DNS servers or location IP resolution tables via malware to redirect unsuspecting users to a fake website. On the fraudulent site, the customer experience mimics that of the online bank, and users are prompted to enter their online banking credentials.

Increasingly, cyber criminals are leveraging these attacks against new channels: small offices and home offices. A recent study released by Team Cymru looks at this attack vector in depth and shows that this is a growing trend in online bank fraud. In this method, malware is loaded to the router and automatically changes its DNS settings to malicious Web addresses for targeted sites. An end user attempting to access an online banking site will be redirected automatically to the malicious site without warning. When a user unsuspectingly logs in to the fraudulent site, their authentication credentials can be captured and stolen by cyber criminals and leveraged for online fraud.

Pharming Attacks on the Rise

Pharming attacks on small office and home office routers have become more prevalent in specific countries — like Brazil, for example — and have moved to other areas of the world. Since users typically do not change their default settings or passwords of their small office or home routers nor update them to patch security vulnerabilities in their software, this type of pharming attack is increasingly attractive for fraudsters. This attack affects all devices accessing the infected router from the local network, including computers, tablets and mobile devices.

Trusteer Rapport has demonstrated zero-day protections against this type of attack. Rapport verifies the secure communication between the browser and the online banking application, thus eliminating the threat transparently without requiring any involvement from the end user. Rapport’s protection extends to defend all devices running Trusteer Rapport, despite the attack occurring on the router and not the end user’s machine. With Rapport, customers are one step ahead of pharmers with the ability to prevent an attack before it even happens.

Read the white paper: Accelerating growth and digital adoption with seamless identity trust

More from Banking & Finance

Black Friday chaos: The return of Gozi malware

4 min read - On November 29th, 2024, Black Friday, shoppers flooded online stores to grab the best deals of the year. But while consumers were busy filling their carts, cyber criminals were also seizing the opportunity to exploit the shopping frenzy. Our system detected a significant surge in Gozi malware activity, targeting financial institutions across North America. The Black Friday connection Black Friday creates an ideal environment for cyber criminals to thrive. The combination of skyrocketing transaction volumes, a surge in online activity…

What’s up India? PixPirate is back and spreading via WhatsApp

8 min read - This blog post is the continuation of a previous blog regarding PixPirate malware. If you haven’t read the initial post, please take a couple of minutes to get caught up before diving into this content. PixPirate malware consists of two components: a downloader application and a droppee application, and both are custom-made and operated by the same fraudster group. Although the traditional role of a downloader is to install the droppee on the victim device, with PixPirate, the downloader also…

Exploring DORA: How to manage ICT incidents and minimize cyber threat risks

3 min read - As cybersecurity breaches continue to rise globally, institutions handling sensitive information are particularly vulnerable. In 2024, the average cost of a data breach in the financial sector reached $6.08 million, making it the second hardest hit after healthcare, according to IBM's 2024 Cost of a Data Breach report. This underscores the need for robust IT security regulations in critical sectors.More than just a defensive measure, compliance with security regulations helps organizations reduce risk, strengthen operational resilience and enhance customer trust.…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today