Other nomination
Winning the Online Banking War
Banking trojans steal money through JavaScript injected into the victim's browser rather than through the malware binary. The paper dissects how these injects hook the DOM to alter transactions and defeat two-factor authentication, catalogues evasion tricks such as obfuscation, control-flow randomisation and DOM rootkits, and proposes a DOM-integrity whitelist defence called MIPS.
Record
- Researcher
- Sean Park
- Published by
- blackhat.com
- Date
- Format
- Recording
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Sean Park, first published at the original source. Preserved copies are kept so the citation survives its host.