Live data from Hacker News

Banking malware in Brazil may be responsible for billions in losses

krebsonsecurity.com

21–28 of 28 posts

Re: Banking malware in Brazil may be responsible for billions in losses

#21
post #20

So many comments asking why people don't use credit cards. The easy answer, already told, is that many Brazilian people don't have bank accounts or credit card. This is only half truth and probably not relevant to the case here, as the malware in question will only affect people accessing their bank accounts through the internet. The "boleto" system is actually a very nice way to handle payments. The boleto mostly su…

To help people from other countries visualize how it works, here is the technical specification for boletos from a major bank: http://www.bb.com.br/docs/pub/emp/empl/dwn/Doc5175Bloqueto.p... (in Portuguese).

The banks can make available to the retailer a machine-readable file containing all the boletos received in the last day (using Febraban's CNAB 240 format, or the older CNAB 400 format). This allows the payment confirmation to be automated.

Re: Banking malware in Brazil may be responsible for billions in losses

#22
post #20

So many comments asking why people don't use credit cards. The easy answer, already told, is that many Brazilian people don't have bank accounts or credit card. This is only half truth and probably not relevant to the case here, as the malware in question will only affect people accessing their bank accounts through the internet. The "boleto" system is actually a very nice way to handle payments. The boleto mostly su…

the "don't have credit cards" is simplistic.

we have a government that listened a little to the people and didn't allowed for banks to own all money like in the US.

in the US you're forced to pay credit card fees (usually on the vendor side, so it's included in the price for everyone, even non cc users, as to not tarnish the reputation of the cc operator charging the fee). there's no way to buy online in the us without paying that.

in Brazil and other civilized counties you can use a payment number, which is like a temporary deposit account number that identify the person providing the funds. and it can't cost extra.

Re: Banking malware in Brazil may be responsible for billions in losses

#23
post #17

Does anyone know what those bank plugins are supposed to do anyway? I never managed to get a good answer for that.

I know some of them can be pretty aggressive, going as far as installing a "root kit" on the machine. At some point one of these plugins conflicted with a Windows 7 update, and caused the affected machines to crash at boot: http://gizmodo.uol.com.br/bug-windows-7-solucao-e-causa/

Re: Banking malware in Brazil may be responsible for billions in losses

#24
post #10

Shameless plug: I recently created a boleto management iOS app called Zebra ( http://zebrapp.co/ ) If you're brazilian and are looking for a better way to handle and pay your boletos, I think it can help you.

How can it help defend against this type of scam?

It seems what is needed seems out of band confirmations?

Re: Banking malware in Brazil may be responsible for billions in losses

#26
post #20

So many comments asking why people don't use credit cards. The easy answer, already told, is that many Brazilian people don't have bank accounts or credit card. This is only half truth and probably not relevant to the case here, as the malware in question will only affect people accessing their bank accounts through the internet. The "boleto" system is actually a very nice way to handle payments. The boleto mostly su…

The closest equivalent to boletos in the UK are payment agents:

https://www.paypoint.com/en-gb

http://www.payzone.co.uk/

I don't believe the numbering is unique to specific bill, but to a specific account, e.g. I'd use the same identifier each time I paid by gas bill.

Re: Banking malware in Brazil may be responsible for billions in losses

#27
post #2

Tangentially, in the documentary The Fog of War, Robert McNamara describes how accounting at Ford was so messed up that they had to weigh the invoices to estimate expenses. So this got me wondering if crooks don't just mail false invoices to large firms in case some pay without checking.

> So this got me wondering if crooks don't just mail false invoices to large firms in case some pay without checking. They do Example: a company I knew (in Canada) displayed some fake invoices for "IP/Trademark registering" in Europe, of course the payment was optional, but if you don't pay attention it gets payed

In my previous companies in Italy we received multiple times requests to renew the registration on some kind of internet company registry in Germany. Fortunately the accounting dept asked us in IT "what's this / should we pay it?" and we directly sent those letters to the trash.

Re: Banking malware in Brazil may be responsible for billions in losses

#28
post #20

So many comments asking why people don't use credit cards. The easy answer, already told, is that many Brazilian people don't have bank accounts or credit card. This is only half truth and probably not relevant to the case here, as the malware in question will only affect people accessing their bank accounts through the internet. The "boleto" system is actually a very nice way to handle payments. The boleto mostly su…

The closest equivalent to boletos in the UK are payment agents: https://www.paypoint.com/en-gb http://www.payzone.co.uk/ I don't believe the numbering is unique to specific bill, but to a specific account, e.g. I'd use the same identifier each time I paid by gas bill.

Having a numbering for a specific account is also possible with Brazilian boleto system, but it is common only for credit cards, which can be paid at any time and at a wide range of values.

Gas and phone codes are always bill-specific. However, if you pay a boleto like this twice, the provider will be informed and generally will give you the chargeback in the next bill. I have already used this as a trick to pay a bill when I was travelling and wouldn't get the most recent bill.

Post reply on HN