Live data from Hacker News

Banking malware in Brazil may be responsible for billions in losses

krebsonsecurity.com

11–20 of 28 posts

Re: Banking malware in Brazil may be responsible for billions in losses

#12
The first comment in the article (from someone who has clearly never left his hometown or is a five year old in disguise):

"Brian, do you know why Brazilians would choose to use Boletos if they aren’t subject to chargebacks? It seems like a silly thing to do, especially when credit cards are acceptable forms of payment practically anywhere."

sigh

Re: Banking malware in Brazil may be responsible for billions in losses

#14
They say it doesn't happen to mobile, but I'm not sure what happens if you root your phone and/or install allow apk install from "untrusted" sources in the Dev Opts.

This kind of scam is old, but there are many, like local DNS redirect, keylogging / input-logging, maybe even a piracy web-browser.

Re: Banking malware in Brazil may be responsible for billions in losses

#15
post #2

Tangentially, in the documentary The Fog of War, Robert McNamara describes how accounting at Ford was so messed up that they had to weigh the invoices to estimate expenses. So this got me wondering if crooks don't just mail false invoices to large firms in case some pay without checking.

Somewhat similar to the 'office supply fraud': http://www.snopes.com/crime/fraud/supplies.asp

Or, for that matter, debt collection agencies sending notices for expired debt, and having small-print at the bottom explaining that you are under no obligation to repay this, but if you respond and/or make a payment, they'll be able to go after you for larger amounts. (I have one on my desk. I might frame it for when I need to look at something and have a chuckle.)

Re: Banking malware in Brazil may be responsible for billions in losses

#16

The first comment in the article (from someone who has clearly never left his hometown or is a five year old in disguise): "Brian, do you know why Brazilians would choose to use Boletos if they aren’t subject to chargebacks? It seems like a silly thing to do, especially when credit cards are acceptable forms of payment practically anywhere." sigh

This is the payment version of "Let them eat cake" (http://en.wikipedia.org/wiki/Let_them_eat_cake for those who don't know)

And of course in Europe Credit Cards are not widespread as well and there are other popular payment options.

Re: Banking malware in Brazil may be responsible for billions in losses

#19
post #2

Tangentially, in the documentary The Fog of War, Robert McNamara describes how accounting at Ford was so messed up that they had to weigh the invoices to estimate expenses. So this got me wondering if crooks don't just mail false invoices to large firms in case some pay without checking.

That's exactly what they do.

One of the scams involves looking up WHOIS for thousands of domains and sending false domain renewal bank slips ("boletos"). Some will pay and never notice it's a scam.

What the article describes is a more sophisticated method using a malware though.

Re: Banking malware in Brazil may be responsible for billions in losses

#20
So many comments asking why people don't use credit cards. The easy answer, already told, is that many Brazilian people don't have bank accounts or credit card.

This is only half truth and probably not relevant to the case here, as the malware in question will only affect people accessing their bank accounts through the internet.

The "boleto" system is actually a very nice way to handle payments. The boleto mostly substitutes mailing checks: the company I owe send me the bill with a numeric code (and a corresponding bar code for convenience), and I can use this code to pay the bill at a bank, supermarket, lottery houses or, of course, directly from my bank account through the internet or ATM.

A boleto is different from a account deposit because each boleto is unique: the code identifies who that specific boleto was sent to, so payment processing is done automatically. No out-of-band bank codes or check handling involved.

Boletos are used in several contexts where a credit card is not appropriate, such as paying the credit card bill. However, it may substitute credit cards sometimes: an online commerce outlet will happily generate a boleto for you to pay instead of paying with credit card. You can then pay for you purchase without revealing personal information, having a credit card or sending checks by mail.

Actually, paper checks are very, very rare in Brazil nowadays, even in business contexts. Most retail business won't accept them anymore.

Also, when you pay a boleto, you get an timestamped authentication code proving you paid it. The company can't allege the check was incorrect, for example. The code may also carry the amount to be paid and/or expiration date, preventing payment of the wrong value of after the due date.

This is actually a very functional system that credit cards cannot completely substitute, even if everyone had a bank account or credit card.

EDIT: clarity and a bit of extra info

Post reply on HN