Fake HSBC “Important : Troubles processing BACs payment ” delivers Trickbot

This example is an email containing the subject of “I have securely shared file(s) with you” pretending to come from HSBC  but actually coming from “James.Holand@hsbcbacs.co.uk” which is a look-a-like,  typo-squatted or other do… Continue reading Fake HSBC “Important : Troubles processing BACs payment ” delivers Trickbot

New coalition aims to advance cybersecurity across sectors, around the world

Six global organizations have joined together to launch The Coalition to Reduce Cyber Risk (CR²). CR² members, including AT&T, Cisco, HSBC, JPMorgan Chase, Mastercard and Microsoft will partner with each other and governments to advance cyber risk… Continue reading New coalition aims to advance cybersecurity across sectors, around the world

Banking Apps Found Vulnerable to MITM Attacks

Using a free tool called Spinner, researchers identified certificate pinning vulnerabilities in mobile banking apps that left customers vulnerable to man-in-the-middle attacks. Continue reading Banking Apps Found Vulnerable to MITM Attacks

Fake HSBC Important – Payment Advice delivers trickbot banking trojan

An email with the subject of Important – Payment Advice pretending to come from HSBC  but actually coming from a look-a-like domain HSBC <no-reply@hsbcpaymentadvice.com> or HSBC <no-reply@hsbcadvice.com>  with a malicious word doc attachment  is today’s latest spoof of a well-known company, bank or public authority delivering Trickbot banking Trojan They are using Continue reading → Continue reading Fake HSBC Important – Payment Advice delivers trickbot banking trojan

Fake spoofed HSBC Payments request delivers Trickbot banking Trojan

An email with the subject of Payments request  pretending to come from HSBC  but actually coming from a look-a-like domain <message@hsbc-mail.co.uk>  with a malicious word doc attachment  is today’s latest spoof of a well known company, bank or public authority delivering Trickbot banking Trojan They are using email addresses and subjects that Continue reading → Continue reading Fake spoofed HSBC Payments request delivers Trickbot banking Trojan

Spoofed HSBC Account secure documents malspam delivers trickbot

An email with the subject of Account secure documents pretending to come from HSBC but actually coming from a look alike domain <noreply@hsbcdocs.co.uk>  with a malicious word doc attachment  is today’s latest spoof of a well known company, bank or public authority delivering Trickbot banking Trojan They are using email addresses and Continue reading → Continue reading Spoofed HSBC Account secure documents malspam delivers trickbot

fake HSBC Bank – 24086 Loan Program Notification malspam delivers hancitor

Continuing with the never ending series of malware downloaders is an email with the subject of HSBC Bank – 24086 Loan Program Notification coming  from noreply9@creditsupport.gdn which delivers what looks like hancitor malware. It is quite unusual for malware authors to use 7zip (7z) compressed ( zip ) files, although most current extraction Continue reading → Continue reading fake HSBC Bank – 24086 Loan Program Notification malspam delivers hancitor

Fake HSBC Payment advice delivers malware

Continuing with the never ending series of malware downloaders is an email with the subject of FW: Payment Advice – Advice Ref:[G32887529930] / Priority payment / Customer Ref:[03132394] pretending to come from HSBC Advising Service <050717.advisingservice@mail.com>. These are quite well detected on VirusTotal but as generic or heuristic detections, so I am Continue reading → Continue reading Fake HSBC Payment advice delivers malware