BackSwap malware finds innovative ways to empty bank accounts

Discussion in 'malware problems & news' started by Minimalist, May 25, 2018.

  1. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    https://www.welivesecurity.com/2018/05/25/backswap-malware-empty-bank-accounts/
     
  2. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Of note is Eset is the only vendor on VT that detects the Javasrcript version of the malware.
     
  3. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Interesting stuff, a banking trojan that doesn't use any code injection. The question is, can this be blocked via HIPS? In the article it's mentioned that it installs event hooks to monitor the browser. Isn't this related to global and window hooking? Also, keyboard and mouse simulation are other things that can be blocked.
     
  4. guest

    guest Guest

    BackSwap Malware Now Targets Six Banks in Spain
    August 22, 2018
    https://securityintelligence.com/backswap-malware-now-targets-six-banks-in-spain/
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.