home.social

#bankingtrojan — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #bankingtrojan, aggregated by home.social.

fetched live
  1. Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign

    Grandoreiro, a notorious banking trojan active since 2016 across Latin America, continues operations despite major law enforcement disruption in 2024. Recent campaigns leverage DLL sideloading techniques, abusing the legitimate Duplicate Files Finder application to execute malicious code. The loader incorporates extensive anti-analysis mechanisms including sandbox detection, virtual machine artifact checks, process blacklisting, and environment profiling to evade automated analysis systems. These defensive checks occur before C2 contact, indicating high priority on avoiding detection. Telemetry from June 2026 shows activity concentrated in Latin America, primarily Mexico, with limited presence in Europe and North America. The malware uses custom string obfuscation combining proprietary decryption with Base64 encoding, and communicates with C2 infrastructure over TCP port 6432 using encrypted requests containing host-specific information.

    Pulse ID: 6a86146ca27454b03a4cbe2d
    Pulse Link: otx.alienvault.com/pulse/6a861
    Pulse Author: AlienVault
    Created: 2026-08-19 20:39:08

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Bank #BankingTrojan #Brazil #CyberSecurity #Europe #InfoSec #LatinAmerica #LawEnforcement #Mac #Malware #Mexico #NorthAmerica #OTX #OpenThreatExchange #RAT #RCE #SMS #SideLoading #TCP #Trojan #bot #AlienVault

  2. Striking gold: Inside the GoldDigger Android malware

    GoldDigger is a sophisticated Android banking trojan that primarily targets mobile banking users in South Africa and across Europe, with evidence suggesting plans for global expansion. The malware employs advanced evasion techniques including a custom packer called 'dpt-shell', anti-debugging mechanisms, and Frida detection. It disguises itself as legitimate airline and shopping applications to deceive victims. GoldDigger exploits Android Accessibility services to perform on-device fraud, steal credentials, intercept SMS-based two-factor authentication, and execute unauthorized transactions. A unique feature is its ability to run targeted banking applications in a virtual environment, allowing complete interception of API calls and runtime behavior. The malware maintains communication with command-and-control servers via encrypted WebSocket protocol, enabling capabilities including screen recording, audio capture, phishing overlays, and remote device manipulation.

    Pulse ID: 6a7c732c803c76b919db7963
    Pulse Link: otx.alienvault.com/pulse/6a7c7
    Pulse Author: AlienVault
    Created: 2026-08-12 13:20:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Africa #Android #Bank #BankingTrojan #CyberSecurity #ELF #Europe #GoldDigger #InfoSec #Malware #MobileBanking #OTX #OpenThreatExchange #Phishing #RCE #SMS #Trojan #bot #AlienVault

  3. Ousaban Trojan Expands to Spain, Portugal with Advanced Evasion Tactics

    Meet Ousaban, a sneaky banking Trojan that's evolved from decade-old tactics to target unsuspecting customers in Spain and Portugal, starting with a clever phishing PDF disguised as a broken file. This highly optimized threat profiles its victims before striking, making it a force to be reckoned with.

    osintsights.com/ousaban-trojan

    #BankingTrojan #Ousaban #Spain #Portugal #Phishing

  4. 🚨 Alert: The new #EternidadeStealer is using WhatsApp to spread malicious files to steal banking and crypto data from users. Watch out and don’t open unexpected attachments, plus verify messages from contacts.

    Read: hackread.com/eternidade-steale

    #CyberSecurity #Malware #WhatsApp #BankingTrojan #InfoSec