Attackers Employ Social Engineering to Distribute New Banking Trojan

GlobalDots
2 Min read

Unknown attackers have begun using a sophisticated, new banking Trojan, dubbed CamuBot, to steal money from the business customers of several major banks in Brazil, a country sometimes used as a testing ground for financial malware that is about to be launched globally.

Reduce your AWS costs by over 50%

Discover your Cloud Saving Potential – Answer just 5 simple questions. AppsFlyer, Playtika, Lufthansa, IBM, top leading companies are already using our FinOps services.

Reduce your AWS costs by over 50%

IBM X-Force security researchers, who have been tracking the threat, this week described the CamuBot campaign as a combination of highly targeted social engineering with malware-assisted account and device takeover. The malware operators have been getting victims to download CamuBot on their systems by disguising it as a required security module — complete with logos and brand imaging — from their banks.

Troublingly, CamuBot has functionality that suggests it has the ability to hijack device driver controls for fingerprint readers, USB keys, and other third-party security peripherals that banks often use as an additional mechanism for authenticating users.

The attackers have typically targeted individuals who are the most likely owners of their organizations’ bank account credentials. They identify themselves as bank employees and ask the victim to browse to a location for checking whether his company’s bank security module is up to date. The validity check always comes up negative, and the targeted individual is then tricked into downloading an “updated” version of the module.

If the victim downloads the module, a fake application appears in the foreground while CamuBot is silently installed in the background and establishes a connection with its command-and-control server. The victim is then redirected to what appears to be his bank’s online portal, where he is prompted to enter his login credentials, which are promptly captured by the attackers.

Image Source

Read more: Dark Reading

Latest Articles

3 IT Infrastructure Costs Increasing in 2024:

As we navigate through the evolving landscape of IT infrastructure, a closer look at the cost trends for 2024 reveals significant shifts. From cloud expenses feeling the pressure of economic changes. With global cloud spending expected to hit over $1 trillion and various sectors facing unique challenges, staying informed is more crucial than ever.  Dive […]

Miguel Fersen Iberia & LATAM Regional Manager @ GlobalDots
26th February, 2024
Justt – IaC

Justt is a chargeback mitigation startup based in Tel Aviv. Chargebacks, as defined, are demands by a credit card provider for a retailer to reimburse losses on fraudulent or disputed transactions. Justt’s objective is to assist merchants worldwide in combating false chargebacks using its proprietary artificial intelligence technology.

GlobalDots
22nd February, 2024
8 FinOps Best Practices for Cutting Cloud Costs

The cloud used to be viewed as a place of significant cost savings: rather than purchasing and maintaining dozens of server stacks, organizations could outsource this and purchase compute power on an as-needed basis. In the ensuing rush to cloud architecture, however, many companies simply lifted-and-shifted their old financial bad habits. The sheer speed of […]

GlobalDots
22nd February, 2024

Unlock Your Cloud Potential

Schedule a call with our experts. Discover new technology and get recommendations to improve your performance.

Unlock Your Cloud Potential