Security researchers identified two malware distribution campaigns that infect customers of Brazilian financial institutions with banking Trojans.

While Cisco Talos observed that the two ongoing malware campaigns use different file types for the initial download stage and infection process, they also noticed some similarities between the two campaigns.

For instance, both campaigns abuse link-shortening services to disguise their distribution methods and employ the same naming convention for files used during the infection process. Researchers also traced both of the operations back to an email generation tool hosted in an Amazon S3 bucket, which they believe attackers are using to create a botnet.

Cisco Talos determined that the ultimate purpose of the campaigns is to deliver one of two banking Trojans to Brazilian financial institutions. Both of the final payloads exfiltrate data to a command-and-control (C&C) server and come equipped with a keylogger. However, while one Trojan attempts to steal customers’ payment card security codes, the other targets two-factor authentication (2FA) codes.

A Surge in Banking Trojans

News of these campaigns comes amid a surge in banking Trojan activity across a variety of platforms. In the second quarter of 2018, Kaspersky Lab detected 61,045 installation packages for mobile banking Trojans. That number was more than triple the amount observed in Q1 of 2018, and it far surpassed the totals observed over the previous year.

This growth continued through the summer. In August, Check Point noted that attackers had doubled their use of banking Trojans over the previous two months. In particular, researchers tracked increased activity for the Ramnit banking Trojan, a threat that rose to sixth place on Check Point’s August 2018 “Most Wanted Malware” list.

How to Protect Your Organization From Financial Cyberthreats

Security professionals can help defend against campaigns distributing banking Trojans by using endpoint security solutions designed to protect against fraud techniques. In addition, security teams can challenge the spam botnets used to deliver these threats by enabling email filtering and similar protections on corporate systems.

Sources: Cisco Talos, Kaspersky Lab, Check Point

More from

2022 Industry Threat Recap: Finance and Insurance

The finance and insurance sector proved a top target for cybersecurity threats in 2022. The IBM Security X-Force Threat Intelligence Index 2023 found this sector ranked as the second most attacked, with 18.9% of X-Force incident response cases. If, as Shakespeare tells us, past is prologue, this sector will likely remain a target in 2023. Finance and insurance ranked as the most attacked sector from 2016 to 2020, with the manufacturing sector the most attacked in 2021 and 2022. What…

X-Force Prevents Zero Day from Going Anywhere

This blog was made possible through contributions from Fred Chidsey and Joseph Lozowski. The X-Force Vulnerability and Exploit Database shows that the number of zero days being released each year is on the rise, but X-Force has observed that only a few of these zero days are rapidly adopted by cyber criminals each year. While every zero day is important and organizations should still devote efforts to patching zero days once a patch is released, there are characteristics of certain…

And Stay Out! Blocking Backdoor Break-Ins

Backdoor access was the most common threat vector in 2022. According to the 2023 IBM Security X-Force Threat Intelligence Index, 21% of incidents saw the use of backdoors, outpacing perennial compromise favorite ransomware, which came in at just 17%. The good news? In 67% of backdoor attacks, defenders were able to disrupt attacker efforts and lock digital doorways before ransomware payloads were deployed. The not-so-great news? With backdoor access now available at a bargain price on the dark web, businesses…

Hack-for-Hire Groups May Be the New Face of Cybercrime

Google’s Threat Analysis Group (TAG) recently released a report about growing hack-for-hire activity. In contrast to Malware-as-a-Service (MaaS), hack-for-hire firms conduct sophisticated, hands-on attacks. They target a wide range of users and exploit known security flaws when executing their campaigns. “We have seen hack-for-hire groups target human rights and political activists, journalists and other high-risk users around the world, putting their privacy, safety and security at risk,” Google TAG says. “They also conduct corporate espionage, handily obscuring their clients’ role.”…