October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

KL-Remote: How a Remote Overlay Toolkit Enabled Online Banking Fraud

KL-Remote was a criminal toolkit reported in 2015 that used malware, a bank-themed overlay and remote control to steal credentials and act during online-banking sessions.
From TheFinanceBase Team4 min to read

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

KL-Remote was a criminal toolkit described by IBM Security Trusteer researchers in 2015. In the reported attacks, malware on a victim’s computer let an operator monitor a banking session, place a convincing prompt over the legitimate bank page, collect authentication details and act through the victim’s device. The case illustrates why a familiar login or a one-time code alone may not prove that the account holder initiated a transaction when a computer is under remote control.

What is a remote overlay attack?

A remote overlay attack uses malware on a person’s device to interfere with an otherwise legitimate online-banking session. Unlike a basic phishing site, which imitates a bank on a separate web address, the reported KL-Remote technique operated on the infected endpoint while the customer visited the real bank. SecurityWeek described the operator viewing the victim’s desktop and keystrokes, controlling the mouse and keyboard, and displaying a tailored prompt over an image of the banking page. SecurityWeek’s January 14, 2015 report said the prompt could request account credentials and a one-time password.

How did KL-Remote steal online banking credentials?

  1. Monitor for a bank visit. The toolkit watched an infected user’s online activity for visits to targeted financial institutions. When a target site was opened, the operator received an alert and information about the victim’s device.
  2. Observe and control the session. The operator could see the desktop and typing and remotely use the mouse and keyboard.
  3. Present a bank-themed prompt. A prompt appeared over the banking page and could ask for login credentials and a one-time password. The victim was then shown a waiting message.
  4. Act through the victim’s computer. While the user saw the overlay, the operator could use the computer to access the bank account and carry out activity behind it. SecurityWeek characterized the process as requiring manual intervention, rather than being wholly automatic.

This combination of a legitimate banking session and a remotely controlled endpoint is central to the case: the prompt did not merely send a customer to a counterfeit bank website.

Could KL-Remote bypass two-factor authentication?

IBM’s April 2015 X-Force presentation listed username and password, two-factor authentication, and device identification among traditional protections the reported KL-Remote attack could bypass. The mechanism helps explain the claim: an operator able to capture a requested one-time code and act through the already-in-use computer could exploit trust in that session and device. IBM’s presentation documents the toolkit in that historical context.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

This is evidence about the reported toolkit and its described workflow in 2015, not proof that every modern multifactor-authentication method is ineffective. Authentication can establish that valid credentials or a code were supplied; it cannot, by itself, establish that the account holder knowingly initiated each action on a compromised endpoint.

Where was KL-Remote reported, and when?

SecurityWeek reported observed use in Brazil and said the phishing prompts were written in Portuguese. The report said researchers believed the toolkit could be adapted for other countries, but that possibility is not evidence of deployment elsewhere. SecurityWeek published its account on January 14, 2015; IBM’s presentation is dated April 2015. Those sources describe a historical case and do not establish whether KL-Remote remains active, how prevalent remote-overlay fraud is today, or current losses from it.

Rank #2
Yubico - YubiKey 5 Nano C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (Nano USB-C)
  • POWERFUL SECURITY KEY: The YubiKey 5C Nano is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C Nano secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: The YubiKey 5C Nano is designed to stay plugged into your device via USB-C. Simply tap it to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

How can banks detect this kind of fraud?

The contemporary SecurityWeek account pointed to several signals for banks and other service operators. None is a guarantee on its own; their value is in looking for inconsistencies across the device, session and transaction.

  • Endpoint evidence: signs of malware on a customer’s device.
  • Browsing behavior: unusual patterns during online banking.
  • Remote control: use of remote-access tools to log in.
  • Transaction behavior: activity that is unusual for the account.

The practical lesson is to assess more than whether a login succeeded or a device was recognized. A session may appear authenticated while an operator controls the endpoint and the customer sees a misleading overlay.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Cryptnox FIDO2 Security Key NFC Smart Card for 2FA MFA Passwordless Login
  • FIDO2 CERTIFIED: FIDO Alliance Certified FIDO2 v2.1 and CTAP Level 1 for 2FA and MFA on Google Microsoft Apple GitHub login.gov AGOV SwissID and any WebAuthn service
  • PASSKEY READY: Works as a hardware passkey for passwordless sign-in where the service enables it and as a U2F and WebAuthn security key everywhere else
  • CERTIFIED SECURITY: NXP JCOP 4.5 secure element rated Common Criteria EAL6+ (augmented)
  • TAP OR INSERT: Dual NFC ISO 14443 and contact ISO 7816 interface in an ID-1 format smart card that is passive and battery-free
  • BUILT TO LAST: Passive smart card made in Switzerland designed by Swiss company Cryptnox and backed by a 2 year manufacturer warranty

What does the case mean for customers and financial institutions?

For customers

The mitigation emphasized in contemporary reporting was preventing malware infection at the endpoint. Keep devices and software maintained, use reputable endpoint protection, and treat unexpected requests for banking credentials or one-time codes with caution. The KL-Remote report does not establish that any particular consumer product is required or that one tool can prevent every account-fraud scenario.

For banks and service operators

Detection needs to account for endpoint, session and transaction signals rather than relying on a successful authentication event alone. IBM’s April 2015 presentation gave broader security recommendations: keep threat intelligence current, maintain an accurate asset inventory, patch infrastructure, implement mitigating controls, instrument environments for detection, and practice incident response. These are general recommendations in that presentation, not a current product endorsement or measured evaluation of particular controls.

Rank #4
Thetis Pro For Business - FIDO2 Security Key L2 MFA & NFC Passkey Access For School ERP, Employee Online Account, Compatible with Coinbase Google Workspace Apple ID Window Salesforce,Dual USB A +USB C
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L2 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Universal Connectivity (USB-C, USB-A, & NFC): Designed for PCs, Macs, iPhones, and Android. For mobile use, simply unfold the key, align it with your phone’s NFC antenna, and hold for a few seconds to authenticate.
  • Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
  • Fully compatible with ID Austria, this hardware key meets the mandatory FIDO2 Level 2 (L2) security standard. Check FIDO2 compatibility before purchase - Known limitations: Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC is supported only through mobile authentication, Not MacOS/windows.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the 2015 report does—and does not—establish

Trusteer’s Ori Bach described the significance of packaged criminal tooling in SecurityWeek’s account: “Toolkits such as KL-Remote — which package a preconfigured fraud flow in a user-friendly GUI — greatly expand the pool of people who can commit banking fraud.” Bach continued: “With the toolkit, a criminal with basic technical skills can perform high-end fraud attacks that can circumvent strong authentication.” The quotation refers to the toolkit and threat as reported at the time.

The article also cited a figure of $264 million in Brazilian internet-banking fraud in 2013, attributing it generally to “studies.” It did not identify the original study or publisher, so that number cannot be treated here as a fully attributable statistic or a current measure. The available sources provide no current named estimate for KL-Remote infections, remote-overlay fraud prevalence or associated losses.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
OneSpan DIGIPASS® FX7 Two-Factor authentication (2FA) Security Key, Connect via USB-C FIDO Certified - FIDO2, Protect Accounts Online, Passwordless Authentication, Secure Passkey, Phishing Resistent
  • Phishing-Resistant Security: Guard against cyber threats like phishing and credential theft with bank-grade security from OneSpan, trusted by over 60% of the world’s largest financial institutions.
  • Effortless, Password-Free Authentication: Experience easy, one-touch security with this FIDO2-certified device. Say goodbye to passwords and hello to secure, passwordless access in seconds.
  • Portable and User-Friendly: Compact and easy to use, DIGIPASS FX7 ensures secure access anytime. Simply plug into a USB-C port on a laptop, desktop, tablet, or phone, and tap to authenticate. For added security, a PIN entry option is also available.
  • Broad Compatibility: This single security key grants access to over 1,000 FIDO2-enabled services, compatible with Microsoft 365, Google Workspace, AWS, Salesforce, Okta, OneLogin, Ping Identity, and more.
  • Plug-and-Play Activation: With a zero-footprint design, DIGIPASS FX7 requires no software installation or complex configuration. Just plug it in, and it’s ready to go.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.