• Home
  • Videos
  • Contact
  • Subscribe to Newsletter
  • Subscribe to Re:ID Magazine
  • Twitter
  • RSS
SecureIDNews
  • Markets »
  • Corporate
  • Education
  • Financial
  • Government
  • Health
  • Transit
  • Technologies »
  • Biometrics
  • Contactless
  • Digital ID
  • NFC
  • RFID
  • Smart Cards

Time: 0 :0

You are here:

  • Home
  • Hackers use Citadel Trojan to access airports’ apps

Hackers use Citadel Trojan to access airports’ apps

17 August, 2012

By: Jill Jaracz

category: Digital ID, Financial

0

Trusteer has uncovered a Man in the Browser attack directed at VPN users at an international airport hub.

The hackers have used the trojan to steal airport employee credentials, with which they can then access internal airport applications. Having VPN access allowed the hackers to get into the system and tamper with any information and applications that particular employee is authorized to use.

The Citadel Trojan attack got the credentials through a combination of form grabbing and screen capture and was able to procure a username, password and one-time passcode from the airport’s authentication vendor.

With form grabbing, the attackers were able to steal the username and password. Through screen capture, the attackers could take a snapshot of the image created by the strong authentication product. Although the strong authentication tool can prevent attacks by a form grabber, the screen capture method allows the attacker to use the permutation of digits and one-time code to reproduce the static password.

Trusteer notes that these attacks are normally focused on financial services to conduct online banking fraud; however, they are being launched on other industries, making security and protection increasingly important to all businesses.


Tags: Banking, Internet Security

recommend to friends

Related News

Organizations replace usernames and passwords with one-time passcodes

18 June, 2013

SecureKey adds hardware-based authentication to MasterPass

14 June, 2013

Next-gen gaming: Too much authentication?

14 June, 2013

Financial services research committee makes identity a priority

12 June, 2013

SecureIDNews
BACK TO TOP

re:ID Magazine



Read current issue online

CR80News Magazine



Read current issue online

Twitter feed

Follow on Twitter
  • About
  • Advertise
  • Store
  • re:ID
  • Subscribe
  • Twitter
  • RSS

© 2013-2014 AVISIAN Publishing. All rights reserved. info@avisian.com

Close

Enter the site

Login

Password

Remember me

Forgot password?

Login
Skip to toolbar
    • WordPress.org
    • Documentation
    • Support Forums
    • Feedback
Log Out