Joke Collection Website - Blessing messages - Security issues of mobile payment

Security issues of mobile payment

Virus infection

A large number of mobile payment viruses have broken out rampantly, including the "pseudo-Taobao" virus that pretends to be a Taobao client and steals user account and password privacy, and steals the privacy of more than 20 mobile banking accounts A series of high-risk mobile payment viruses such as "Bank Thief" and "Rockworm" infected the first China Construction Bank APP. The main typical viruses for mobile payment software are further divided into typical viruses for e-commerce APPs, typical viruses for third-party payment APPs, typical viruses for financial management APPs, typical viruses for group purchase APPs, and typical viruses for banking APPs. According to statistics from Tencent Mobile Security Laboratory, in 2014, emerging mobile payment viruses such as "trust-stealing zombies" that forwarded users' mobile phone verification codes posed a serious threat to mobile phone users' payment security.

Mobile phone vulnerabilities

In 2014, the security situation of mobile payment became increasingly grim. Android system vulnerabilities have exacerbated this situation. On February 18, 2014, Wuyun, a domestic vulnerability reporting platform, issued an emergency warning stating that there were security flaws in Taobao and Alipay authentication. Hackers could simply use this vulnerability to log in to other people's Taobao/Alipay accounts for operations. It was unclear whether it would affect Yu'e Bao and other businesses. There are three main related Android phone vulnerabilities that pose a greater threat to mobile payment security: MasterKey vulnerability, Android horse-mounting vulnerability and SMS fraud vulnerability.

Fraudulent phone calls and text messages

Fraudulent text messages and harassing phone calls also pose certain mobile payment risks. Tencent Mobile Security Lab has monitored that, in addition to inducing mobile phone users to make bank transfers through fraudulent and harassing phone calls, fraudsters also mainly send fraudulent text messages with phishing URLs or malicious Trojan program download links. These malicious phishing URLs often induce users to log in. Malicious fraudulent websites, etc., guide users to make shopping payments, and prize-winning phishing scams have become more frequent. Among the key cases, there are three categories: online banking upgrade, U-shield invalidation fraud, social security fraud and popular program lottery winning fraud.