Home Resources Blog Attackers Employ Social Engineering to Distribute New Banking Trojan

Attackers Employ Social Engineering to Distribute New Banking Trojan

Admin Globaldots
07.09.2018
image 2 Min read

Unknown attackers have begun using a sophisticated, new banking Trojan, dubbed CamuBot, to steal money from the business customers of several major banks in Brazil, a country sometimes used as a testing ground for financial malware that is about to be launched globally.

IBM X-Force security researchers, who have been tracking the threat, this week described the CamuBot campaign as a combination of highly targeted social engineering with malware-assisted account and device takeover. The malware operators have been getting victims to download CamuBot on their systems by disguising it as a required security module — complete with logos and brand imaging — from their banks.

Troublingly, CamuBot has functionality that suggests it has the ability to hijack device driver controls for fingerprint readers, USB keys, and other third-party security peripherals that banks often use as an additional mechanism for authenticating users.

The attackers have typically targeted individuals who are the most likely owners of their organizations’ bank account credentials. They identify themselves as bank employees and ask the victim to browse to a location for checking whether his company’s bank security module is up to date. The validity check always comes up negative, and the targeted individual is then tricked into downloading an “updated” version of the module.

If the victim downloads the module, a fake application appears in the foreground while CamuBot is silently installed in the background and establishes a connection with its command-and-control server. The victim is then redirected to what appears to be his bank’s online portal, where he is prompted to enter his login credentials, which are promptly captured by the attackers.

Image Source

Read more: Dark Reading

Learn More

Cloud Cost Optimization: A Strategic Approach to Business Expansion
Cloud Cost Optimization
Admin Globaldots 18.05.23

FinOps is a strategic framework designed to manage and optimize cloud costs effectively. It’s a transformative approach that brings financial accountability to the forefront of the variable spend model of cloud computing. This model allows businesses to gain a firm grip on their cloud expenses, ensuring that every dollar spent is accounted for and utilized […]

Read more
AWS Data Transfer Cost Optimization: Everything You Need to Know
Cloud Cost Optimization
Admin Globaldots 17.05.23

While AWS services provide a wealth of mission-critical services – storing over 2.2 trillion objects in S3 – many organizations are left floundering in the solution’s complex pricing structures. Spanning transfer types and geographies, data transfer costs can be hugely unpredictable and rapidly get out of hand.  Below, we leverage decades of industry experience to […]

Read more
Real-Life Use Case: Automated K8s Optimization Cuts 91% of FinTech Firm’s Cloud Costs
Cloud Cost Optimization
Admin Globaldots 10.04.23

Containers are the foundation of today’s hyper-agile DevOps landscape. Developers can enjoy the reliability of a single environment to run code, with no unexpected hiccups or changes between testing and production. Segmented applications benefit from faster and more efficient delivery, as each functionality evolves via its own isolated lifecycle. As powerful as the foundation that […]

Read more
Unlock Your Cloud Potential
Schedule a call with our experts. Discover new technology and get recommendations to improve your performance.
Book a Demo