Security researchers have warned that cybercrooks might be able to compromise online bank accounts even in cases where banks use SMS messages to authorise transactions.
The approach relies on first compromising a targeted user's computer using a variant of the ZeuS banking Trojan before infecting the same user's smartphone. Thereafter it would be possible to initiate a transaction and authorise it following the receipt of an SMS message to a second compromised device.
Full Story @ The Register
21sec Security blogpost on Mitmo (man-in-the-mobile) attack method