This site uses cookies. By continuing to browse this site you are agreeing to our use of cookies. Find out more.X

34 European banks hit by Android app security attacks

Share this article:

Banks need to put their heads together to develop common and more secure methodologies says Sarb Sembhi, STORM Guidance, following operation Emmental.

34 European banks hit by Android app security attacks
34 European banks hit by Android app security attacks

"Most of these attacks are focused solely on Android because of the lack of software patches for the OS and the deployment method of waiting for carriers to 'personalise' the new OS and firmware releases. This model is broken because it is not in the carriers and resellers interests for users to update; they would rather get additional sales revenue from new handset sales," he explained.

Armstrong - who is a SANS Institute instructor - went on to say that Apple, on the other hand, has a much better internal security model and users get patches long after the handset has been sold. This service comes with a price tag, but I don't see why users must pay more to be secure in this day and age," he said.

"If Google does not fix this growing problem, then with its new Nokia handset skills, Microsoft could steal a large middle ground between the premium Apple handset and the often orphaned and malware-targeted Android camp. I for one am looking at a Windows phone for my next purchase," he added.

Sarb Sembhi, a director with STORM Guidance, said the findings of the report highlight the need for banks to put their heads together - as other organisations have done - to develop common and more secure methodologies for the mobile phone and software industries to develop.

The attack model, he added, is also highly sophisticated in that the cybercriminals have established five or six fallback positions to employ, in the event that one or more of their attack methodologies are compromised.

"Banks need to understand what attack model the cybercriminals are looking at, and then get together to discuss the issue, most notably how the security of the Android platform can be enhanced to stop things like this going wrong," he explained.     

Page 2 of 2
Share this article:

SC webcasts on demand

This is how to secure data in the cloud


Exclusive video webcast & Q&A sponsored by Vormetric


As enterprises look to take advantage of the cloud, they need to understand the importance of safeguarding their confidential and sensitive data in cloud environments. With the appropriate security safeguards, such as fine-grained access policies, a move to the cloud is as, or more, secure than an on-premise data storage.


View the webcast here to find out more

More in News

VC cyber security funding tops £850 million

VC cyber security funding tops £850 million

A new study from US-based research firm CBI Insights reveals that corporate cyber security investments have risen five-fold since 2009, with 30 percent growth in the last year alone.

Russian/Chinese cyber-security pact raises concerns

Russian/Chinese cyber-security pact raises concerns

News that Russia and China are set to sign a cyber-security treaty next month have left Western cyber experts unsure whether it is a threat or a promising development.

UK police arrest trio over £1.6 million cyber theft from cash machines

UK police arrest trio over £1.6 million cyber ...

London Police have arrested three suspected members of an Eastern European cyber-crime gang who installed malware on more than 50 bank ATM machines across the UK to steal £1.6 million.