Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
malicious JavaScript through compromised web sites or advertisements led to the EK that exploited Adobe Flash vulnerabilities CVE-2014-0569 or CVE-2015-3133. We confirmed that final payload in both cases was KRBanker. | Unit 42 has been tracking "KRBanker" AKA 'Blackmoon'... This campaign specifically targets banks of the Republic of Korea.
malicious JavaScript through compromised web sites or advertisements led to the EK that exploited Adobe Flash vulnerabilities CVE-2014-0569 or CVE-2015-3133. We confirmed that final payload in both cases was KRBanker. | Unit 42 has been tracking "KRBanker" AKA 'Blackmoon'... This campaign specifically targets banks of the Republic of Korea.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
malicious JavaScript through compromised web sites or advertisements led to the EK that exploited Adobe Flash vulnerabilities CVE-2014-0569 or CVE-2015-3133. We confirmed that final payload in both cases was KRBanker. | Our analysis shows that KRBanker has been distributed through web exploit kits (EK) and a malicious Adware campaign.
It then registers the compromised system with the C2 server by sending the following HTTP GET request
The latest version of the threat employs Proxy Auto-Config(PAC)... The adversaries abuse this feature for Pharming. To configure this, the Trojan starts a local proxy server
Researchers at ALYac had reported previously, on KRBanker employing hosts file modification and local DNS proxy techniques to redirect HTTP traffic.
Several of the more well-known legitimate services include OneDrive, Dropbox, MediaFire, Discord, Google services such as Docs and Drive, GitHub, and WeTransfer.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
KrBanker is a banking trojan designed to steal financial information and credentials from victims, particularly targeting users in Chinese-speaking regions.
Mentioned for code similarity in a PE-module loader; not part of the incident.
Banking trojan targeting Korean financial institutions. It is distributed via the KaiXin exploit kit and NEWSPOT adware, uses process hollowing for execution, performs pharming via Proxy Auto-Config to redirect victims to fraudulent banking sites, steals certificates from the NPKI directory, and can terminate Ahnlab V3 security software.
A banking trojan targeting South Korean financial institutions. It is distributed via the KaiXin exploit kit and the NEWSPOT adware campaign, uses process hollowing for execution, retrieves pharming server addresses via Qzone profile data, abuses Proxy Auto-Config to redirect victims to fraudulent banking sites, steals certificates from the NPKI directory, and can terminate Ahnlab V3 security software.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.