Jeff Fu Bangcle Security – SecNeoLtd. Win the Cyberwar on Mobile Banking and Payments
You Probably Already Know About Mobile Banking Threats But you might not know there’s an entire illegal industry dedicated to mobile banking. Do you know what keys Cybercriminals have? How they steal money from Android App?
2013Malware Threats on Mobile 2013 • 2013: • 143,211 New malwares • 3,905,502 Malicious installation packages For the 259 new malware families on Q3, 2013 2011 -2013 In total: Approximately 10,000,000 unique malicious installation packages
2013 Malware Threats on Android 2013 Android remains a prime target for malicious attacks. 98.05% of all malware detected in 2013 targeted this platform, confirming both the popularity of this mobile OS and the vulnerability of its architecture.
2013 Malware Target Mobile Banking 2013 2013 The number of mobile banking malware The cyber industry of mobile malware is becoming more focused on making profits more effectively. I.e., mobile phishing, theft of credit card information, money transfers from bank cards to mobile phones and from phones to the criminals’ e-wallets. 2013 was marked by a rapid rise in the number of Android banking Trojans.
The Geography of Mobile Threats 2013 Countries where users face the greatest risk of mobile malware infection(the percentage of all attacked unique users)
Mobile Banking Virus-Svpeng Svpeng detected by Kaspersky as Trojan-SMS.AndroidOS.Svpeng.A • Collects phone information • Steals voice call SMS messages • Steals money from the victim’s bank account • Steals logins and passwords to online banking accounts • Steals bank card information (the number, the expiry date, CVC2/CVV2) ,
My App Is Already Safe Enough My app is good designed, I considered all the potential risks. My app is good programed by senior engineers. My app is completely tested, all the bug is fixed. My app is published to the Google Market. My customers installed the official released Apps. Yes, I believe you have done all what you can do But your App is still in danger
Dynamic injection Demo Hacker injected the payment components Hacker intercepted the transaction data before it is encrypted Hacker modified the account ID and user name The money is transferred to hacker’s account Hacker tamper the invoice message or SMS and changed them back to original transaction account and user name
Root Cause for All These Attacks Integrity protection failure of Mobile Banking App is the root cause for the most attacks. • Static integrity protection failure • Dynamic integrity protection failure We need to make sure: The App used by the customers is not tamped and repacked The App is always running the same as designed The information in the App can not be accessed and modified All the security logic can not be bypassed
Financial App Protection 2013 The leading App Security Provider in the world In past 3 years, Bangcle provides services to: 100+ Financial and e-Payment Apps 500+ Business App developers Our security products covered more than 300,000,000 smart devices Financial App Integrity Protection Financial App Runtime Protection Financial App Data Protection
Join our Workshop Enable Enterprise-grade Security into your Mobile Apps Schedule: March 19, 4:00 PM ~ 4:45 PM Join us to get more detail information about Bangcle Mobile Banking Security Solution