A bank experienced an attack on the SMS channel used to authenticate online banking transactions. Customers infected with PC-based financial malware were asked to install a malicious Android mobile application. The malicious application was permitted to access the devices SMS channel and redirected SMS one-time passwords (OTP) to the fraudsters. Banks should incorporate mobile device risk into their risk engine analysis. IBM Security Trusteer Pinpoint Criminal Detection incorporates these risk indicators, discovered by different components of the IBM security Trusteer fraud prevention platform.”]

