A lookalike banking app can steal your active session token, letting a stranger drain your account without ever knowing your password. Learn how overlay attacks work and how to protect yourself with biometric re-authentication. Chapters: 00:00 The Silent Thief 00:12 No Alerts, No Clues 00:25 What is a session token? 00:40 Trusted for weeks 00:56 The new password theft 01:08 32% increase 01:20 Overlay attacks dominate 01:36 Biometric Re-auth 01:50 Token Invalidated 02:06 Check Your Settings 02:22 Why Most Apps Are Vulnerable 02:37 75% Have Flaws 02:53 Check Your Settings 03:07 Active Sessions 03:20 Enable Biometric Re-auth 03:36 MAKE IT A HABIT 03:52 Permissions Granted 04:08 Credentials Harvested 04:24 Token Replayed 04:40 Money Moved 04:56 Why You're a Target 05:12 The Real Solution 05:28 The 45% Gap Sources & further reading: ⢠Zimperium Mobile Banking Heists Report ā Annual report on mobile banking malware trends and statistics. ⢠ThreatFabric Brokewell Analysis ā Technical analysis of the Brokewell trojan and its overlay attack capabilities. ⢠OWASP Mobile Application Security Verification Standard ā Standard for mobile app security, including session management and biometric authentication. ⢠NIST Digital Identity Guidelines ā Guidelines on authentication and session management, including biometric re-authentication. ⢠Kaspersky Mobile Threats Report ā Annual report on mobile malware statistics. ⢠IBM X-Force Threat Intelligence Index ā Report on cybersecurity threats, including mobile banking malware techniques.











