5 Mar 2024 - DBS Bank (Hong Kong) Limited (“The Bank”) would like to alert our customers and the public of the Mobile Malware Advisory for iOS users.
Beware of scammers specifically targeting Apple iPhone and iPad users using mobile malware. This malware is designed to collect sensitive information (e.g. facial recognition data, identity documents etc) and intercept SMS messages. Scammers make use of this facial data, combined with ID documents and the ability to intercept SMS, to gain unauthorized access to the victim’s banking account.
The scammers distribute this malware via TestFlight, Apple’s mobile application testing platform, or social engineer potential victims to install a Mobile Device Management Profile (MDM) which would allow the scammer complete control over the victim’s device and access to the victim’s banking account for unauthorized banking transactions.
If you suspect that your device is infected by malware, do this immediately:
- Turn on airplane mode on your phone or turn off your phone.
- Call DBS immediately so we may help you.
- Check and remove any suspicious MDM profiles by going to Settings > General > VPN & Device Management.
- Verify that apps only have permissions that they should.
To Protect Yourself:
- Only download mobile apps from official app stores like Google Play Store and Apple App Store.
- Official app stores have security measures to minimize your risk of installing a malicious app. However, always check the reviews and ratings of apps to ensure their trustworthiness. Never sideload apps from third-party websites, emails, SMSes, or social media. Be wary of MDM profiles and TestFlight application installations from unknown parties.
- Pay attention to the permissions an app asks for and use a reputable mobile security software.
- Think twice if an app requests accessibility permissions, full control over your device, or access to sensitive information like SMS and emails. These requests are often red flags for malicious activities. Consider using reputable mobile security software to detect and block any malicious apps or alert you to potential risks.
If customers are concerned that they may have disclosed their personal information or have conducted any transactions through such channel, they should immediately contact the Police and DBS Bank (Hong Kong) Limited’s bogus calls enquiry hotline at (852) 2290 8345.
DBS Bank (Hong Kong) Limited
星展銀行(香港)有限公司
5 March 2024