Phishing without bait: The in-session password theft attack

Skilled identity thieves can pilfer user names, passwords and other sensitive data for banking sites without using e-mail lures and other other social engineering tactics.
According to a security advisory from Trusteer, hackers can launch what is described as “in-session phishing attacks” using pop-up messages during an active browser session.   The attack technique is somewhat sophisticated [...]

Read entire article

Leave a Reply