Pharming attacks are used by fraudsters to divert users from their online banking website to a fraudulent site. While phishing attacks lure in victims through social engineering tactics, such as a fake email from a bank, pharming attacks target DNS servers or location IP resolution tables via malware to redirect unsuspecting users to a fake website. On the fraudulent site, the customer experience mimics that of the online bank, and users are prompted to enter their online banking credentials.

Increasingly, cyber criminals are leveraging these attacks against new channels: small offices and home offices. A recent study released by Team Cymru looks at this attack vector in depth and shows that this is a growing trend in online bank fraud. In this method, malware is loaded to the router and automatically changes its DNS settings to malicious Web addresses for targeted sites. An end user attempting to access an online banking site will be redirected automatically to the malicious site without warning. When a user unsuspectingly logs in to the fraudulent site, their authentication credentials can be captured and stolen by cyber criminals and leveraged for online fraud.

Pharming Attacks on the Rise

Pharming attacks on small office and home office routers have become more prevalent in specific countries — like Brazil, for example — and have moved to other areas of the world. Since users typically do not change their default settings or passwords of their small office or home routers nor update them to patch security vulnerabilities in their software, this type of pharming attack is increasingly attractive for fraudsters. This attack affects all devices accessing the infected router from the local network, including computers, tablets and mobile devices.

Trusteer Rapport has demonstrated zero-day protections against this type of attack. Rapport verifies the secure communication between the browser and the online banking application, thus eliminating the threat transparently without requiring any involvement from the end user. Rapport’s protection extends to defend all devices running Trusteer Rapport, despite the attack occurring on the router and not the end user’s machine. With Rapport, customers are one step ahead of pharmers with the ability to prevent an attack before it even happens.

Read the white paper: Accelerating growth and digital adoption with seamless identity trust

More from Banking & Finance

DORA and your quantum-safe cryptography migration

5 min read - Quantum computing is a new paradigm with the potential to tackle problems that classical computers cannot solve today. Unfortunately, this also introduces threats to the digital economy and particularly the financial sector.The Digital Operational Resilience Act (DORA) is a regulatory framework that introduces uniform requirements across the European Union (EU) to achieve a "high level of operational resilience" in the financial services sector. Entities covered by DORA — such as credit institutions, payment institutions, insurance undertakings, information and communication technology…

Web injections are back on the rise: 40+ banks affected by new malware campaign

8 min read - Web injections, a favored technique employed by various banking trojans, have been a persistent threat in the realm of cyberattacks. These malicious injections enable cyber criminals to manipulate data exchanges between users and web browsers, potentially compromising sensitive information. In March 2023, security researchers at IBM Security Trusteer uncovered a new malware campaign using JavaScript web injections. This new campaign is widespread and particularly evasive, with historical indicators of compromise (IOCs) suggesting a possible connection to DanaBot — although we…

Virtual credit card fraud: An old scam reinvented

3 min read - In today's rapidly evolving financial landscape, as banks continue to broaden their range of services and embrace innovative technologies, they find themselves at the forefront of a dual-edged sword. While these advancements promise greater convenience and accessibility for customers, they also inadvertently expose the financial industry to an ever-shifting spectrum of emerging fraud trends. This delicate balance between new offerings and security controls is a key part of the modern banking challenges. In this blog, we explore such an example.…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today