The article describes the "sophisticated" attack<p>* Phish the users. The user must fall for this attack.<p>* Prompt the user to MANUALLY download AND install an application on their pc.<p>* Then (if that's not enough) download and MANUALLY install an app on your phone.<p>That's a whole lot of poor decisions on the end user's part. I wouldn't be surprised if these user's wouldn't have just replied to an email with their account number and PIN. Better yet just ask them to mail you cash, seems like something they would do too.<p>Think people. C'mon.