Tag: Banking Malware

WhatsApp Malware ‘Maverick’ Hijacks Browser Sessions to Target Brazil’s Biggest Banks
News

WhatsApp Malware ‘Maverick’ Hijacks Browser Sessions to Target Brazil’s Biggest Banks

Threat hunters have identified similarities between Coyote, a banking malware, and Maverick, a newly revealed malicious program spread through WhatsApp. As stated in a report by CyberProof, the two strains of malware are developed using .NET, aimed at Brazilian users and financial institutions, and possess the same functions for decryption, targeting banking URLs and observing banking apps. Of greater significance, both can disseminate via WhatsApp Web. Trend Micro documented Maverick for the first time in early last month, linking it to a threat actor named Water Saci. The campaign consists of two elements: An autonomous malware known as SORVEPOTEL that disseminates through the desktop web version of WhatsApp and is utilized to send a ZIP file with the Maverick payload. The mali...
New Grandoreiro Banking Malware Variants Emerge with Advanced Tactics to Evade Detection
News

New Grandoreiro Banking Malware Variants Emerge with Advanced Tactics to Evade Detection

It has been discovered that new Grandoreiro banking malware variants use novel strategies to get over anti-fraud systems, suggesting that the malicious software is still being actively developed in spite of law enforcement's attempts to shut it down. Only a portion of this gang was taken into custody; according to a Tuesday study by Kaspersky, the remaining operators behind Grandoreiro are still attacking people worldwide, creating new software, and setting up new infrastructure. Other recently added techniques include mouse tracking, ciphertext stealing (CTS) encryption, and the application of a domain generation algorithm (DGA) for command-and-control (C2) communications read more about New Grandoreiro Banking Malware Variants Emerge with Advanced Tactics to Evade Detection. G...
Grandoreiro Banking Trojan Resurfaces, Targeting Over 1,500 Banks Worldwide
News

Grandoreiro Banking Trojan Resurfaces, Targeting Over 1,500 Banks Worldwide

After being taken down by law enforcement in January, the threat actors responsible for the Grandoreiro banking malware, which targets Windows, have launched a global campaign to resurface since March 2024. Targeting more than 1,500 institutions worldwide, the massive phishing attempts are most likely enabled by other hackers through the use of malware-as-a-service (MaaS) models. These nations include Central and South America, Africa, Europe, and the Indo-Pacific. stated IBM X-Force. Grandoreiro's expansion is probably a change in tactics following attempts by Brazilian authorities to shut down its infrastructure, even though it is best known for its focus on Latin America, Spain, and Portugal. Significant enhancements to the malware itself, indicating ongoing development, go ha...
Carbanak Banking Malware Resurfaces with New Ransomware Tactics
News

Carbanak Banking Malware Resurfaces with New Ransomware Tactics

Updated strategies for ransomware attacks have been observed using the banking malware called Carbanak. In an examination of ransomware attacks that occurred in November 2023, cybersecurity firm NCC Group stated that "the malware has adapted to incorporate attack vendors and techniques to diversify its effectiveness." "Carbanak returned last month through new distribution chains and has been distributed through compromised websites to impersonate various business-related software." Popular business-related programs like HubSpot, Veeam, and Xero are among the spoof tools read more Carbanak Banking Malware Resurfaces with New Ransomware Tactics. Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, ...