• _edge@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    32
    arrow-down
    2
    ·
    10 months ago

    Short version:

    • Malware got onto Windows PC.
    • From the compromised machine, spying on credentials is trivial.

    That’s it. All the analysis about how they inject some code into some browser and communicate with their server is a smoke screen.

    Our most favourite OS is blatantly insecure.

    • BearOfaTime@lemm.ee
      link
      fedilink
      English
      arrow-up
      2
      ·
      10 months ago

      Mac browser too apparently.

      It’s really hard to defend against the human angle. I’ve seen senior management wire $1mil+ to a scammer by emailing the wire info, including PIN. 🤦‍♂️