|
|
|
|
|
by lmkg
4937 days ago
|
|
The attacker bootstraps a small exploit (clicking phishing link) into a much larger one (bank access) by using a multi-step escalation of privileges, that in several cases subverts or co-opts standard chains of trust. Sounds pretty slick to me. Technical sophistication isn't the only form of sophistication. The attack is sophisticated in the trickery it employs to gains the user's trust and give the appearance of being legitimate. A security hole doesn't have to be an OS zero-day to be impressive. |
|