Banking Trojan
In short: A banking trojan steals credentials and transactions during online banking.
In more detail: Well-known families are Zeus, Dridex, TrickBot and Emotet (initially). They often work as man-in-the-browser: the program hooks into the browser and changes pages or transfer data without the address bar showing anything wrong.
In Depth
Methods
- Web injects: additional input fields in real bank pages (for example for TANs).
- Keyloggers and screenshots.
- Manipulation of IBAN and amount before approval.
Protection
Banking app with approval on a separate device, check amounts on the approval device, update systems, use only your own devices for online banking.
See also: Trojans, Keylogger, Online Banking, Phishing