Could malware or remote-access software initiate the payment?¶
Yes. Malware can steal or alter credentials and payment data, while remote tools or compromised sessions can let another person operate the victim's familiar endpoint.
Provider records may still look normal¶
The usual device and IP-related data can appear even when another controller enters details or directs authentication. Device evidence may include installation and connection logs, persistence, extensions, unusual processes and security alerts; communications may show instructions to install software or disclose codes.
Correlate rather than infer from presence¶
Preserve endpoint state, application and connection times, provider sessions, beneficiaries, transactions and communications without casually removing suspected software. Seek specialist malware support where necessary.
Remote software installed on a device is not proof it controlled this event. Align timelines and report endpoint, physically present user and remote controller separately.
The point to remember
Prove remote or malicious control by correlating endpoint, connection, provider and communication records around the payment.