Financial fraudMalware fraud
Malware fraud involves criminals using malicious software to infect a victim’s computer or phone, often after the victim clicks a fraudulent link, opens an attachment, or installs supposedly legitimate software. Once installed, the malware can allow criminals to steal credentials, monitor activity, access accounts, or facilitate unauthorised transactions.
Concrete example
The victim receives an email containing what appears to be an invoice and is instructed to install an “Adobe module” to open it. The installation actually downloads remote-access software, allowing the fraudsters to control the computer and obtain access to payment credentials before making unauthorised transfers. This scenario has been reported by the Luxembourg Police in cases targeting businesses.
Red flags,
stop if
- An unexpected email asks the victim to install software to open a document.
- The victim is instructed to install remote-access software unexpectedly.
- An attachment or link is presented as a security update, invoice, document or technical module.
- The computer suddenly behaves unusually after opening an attachment or installing software.
- Unknown software or browser extensions appear on the device.
- Online banking shows unexpected transactions, new beneficiaries, settings or contact details.
- The victim receives unexpected authentication/LuxTrust requests after installing suspicious software.
- Security software is unexpectedly disabled or generates warnings.