Online Banking Fraud Blog

David García May 27, 2021 9 min read

New Distribution Chain Detected for the Javali Banking Trojan

In recent years, an increase in many banking trojans developed by attackers in Latin American has been detected, in the same way, that their implementations have become more sophisticated as we will see from the recently detected findings.
Start Reading
David Morán May 24, 2021 8 min read

Osiris Banking Trojan for Windows

Morphisec identified a new campaign targeting German clients, characterized by the download of an Osiris client with the ability to communicate via Tor with the command-and-control server (C2).
Start Reading
David García May 17, 2021 8 min read

Sending of a Secure Electronic Comms: New Campaign by the Mekotio Banking Trojan

This isn't the first time that a trojan has used spam campaigns to distribute itself; in fact, it's very common as we've already seen in numerous articles on the blog.
Start Reading
David Morán Mar 15, 2021 2 min read

Toddler: Credential theft overlays and accessibility event logging

In January of 2021, a new family of previously undetected banking malware was discovered. The samples were found on the VirusTotal and Koodous malware analysis platforms.
Start Reading
David García Feb 17, 2021 7 min read

VADOKRIST: Banking malware targeting brazilian entities

Vadokrist is a banking trojan designed to steal banking credentials from mainly Brazilian entities. As such, it shares some of its functionalities with other families such as Grandoreiro or Mekoito, which also target Latin America in particular.
Start Reading
David García Feb 5, 2021 4 min read

2020 Banking Malware Report

2020 has been a year marked by a virus, not one of the ones we usually talk about, but a biological one. COVID-19 monopolized people's attention the past year, including among malware developers.
Start Reading
David García Feb 1, 2021 8 min read

SUNBURST: The backdoor present in SolarWinds Orion updates

On December 8th, FireEye announced that it had suffered an attack in which the company's proprietary Red Team tools were exposed. In response, they published IOCs that allow the use of the tools to be identified.
Start Reading
David García Jan 25, 2021 3 min read

MISPADU: theft of credentials through keylogging

Since June of this year and throughout the last quarter of the year, a banking malware for Windows systems has been increasing its number of victims and stealing their banking credentials. Mispadu is a Brazilian banking trojan that has been around ...
Start Reading
David Morán Jan 20, 2021 9 min read

2021 Banking Malware Trends

This past 2020 has been a year full of high-profile attacks and notorious vulnerabilities, watered with a pandemic climate that cybercriminals have taken advantage of.
Start Reading
David García Jan 7, 2021 3 min read

BBTOK: malware focused on infection and credential theft of Mexicans

BBtok is a new banking trojan whose authors seem to be focused, at least for the time being, on infecting and stealing the credentials of Mexican users. In the event that the victim who executes the dropper sent by email does not use a Mexican ...
Start Reading
David García Jan 2, 2021 3 min read

GRANDOREIRO: fraud based on code injections and phishing

Grandoreiro (also known as Delephant) is one of the most active Windows banking trojans in recent months. Its developers seem to be especially interested in Spanish and Latin American users, since the affected banking entities belong to these ...
Start Reading
David García Dec 21, 2020 9 min read

TrickBoot: TrickBot Module That Interacts with UEFI/BOIS Firmware

TrickBot is a modular malware that has been involved in numerous campaigns, used most recently for the deployment of other malware. The latest enhancements to this malware include a module that inspects devices for firmware vulnerabilities.
Start Reading