Banking and Financial Malware
Online banking and the ability to conduct instantaneous electronic financial transactions over the Internet are now ubiquitous. Cybercriminals have quickly learned that financial fraud conducted over the Web can be very lucrative, setting off an ongoing arms race between malicious software (malware) writers and information security defenders.
Money is the primary motivator for malware authors and their supporters who target financial institutions. Trade secrets, espionage, political, and religious motives also come into play for some threat actors, as they do with other targets. Malware threats can fall into any of the following categories:
- Identity Theft – The stealing of customer login credentials to deplete money from their accounts.
- Corporate Data Intrusion – The penetration of financial services networks to gain access to multiple accounts along with customer and employee data, or to compromise the interests of corporate clients and gain access to profitable inside financial information.
- Transaction Fraud – The alteration of transactions in process by changing the amounts transferred and diverting funds to unauthorized accounts.
- Denial of Service – Prevention of system access to banking customers across large geographic areas, or creation of chaos within the general financial system.
- Advanced persistent threats remain undetected on banking networks, exfiltrating data, stealing funds, and covering their tracks over extended time periods.
- Advanced targeted attacks on the banking and finance industry focus on a particular company, business process, software application, or individual.
- Banking Trojans – malware infects the Web browsers of banking customers, intercepting communications and altering data on its path between the user and the institution. Web “injects” create fake forms or data fields seeking additional user credentials that attackers use to log in and fraudulently transfer funds.
Traditional financial institutions with online banking websites have long been the primary targets of financially-motivated cybercriminals, but recently crooks have turned their attention to new victims hosting high-volume, large-dollar transactions. The automated clearing houses (ACH) of financial transactions in the United States and Single Euro Payments Area (SEPA) credit transfer agencies in Europe are fast becoming the new targets of choice. Security analysts have also noted an alarming rise in mobile malware targeting financial institutions.
The financial services industry is arguably more highly regulated than any other industry. With so much at stake in terms of money and public trust, this sector presents a target-rich environment especially for data thieves.
Norman Shark Network Threat Discovery (NTD) with deep malware analysis is a uniquely powerful solution designed to detect, analyze, and prevent malware from invading enterprise networks, while providing actionable intelligence to IT security teams to mitigate malware-inflicted damage and remediate system vulnerabilities.

