Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Check Point Research recently discovered an active campaign operating and deploying a new variant of the BBTok banker in Latin America.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
these fake interfaces coax unsuspecting users into divulging personal and financial details... tricking the victim into entering the security code/token number that serves as 2FA... In some cases, this capability also aims to trick the victim into entering his payment card number.
The Trojan sends a compressed package containing malicious lnk files to users through phishing emails or other means.
When the user clicks on the malicious lnk, the carried powershell script will be activated to execute subsequent attack payloads.
For Windows 7, the payload just downloads the relevant remote DLL via CMD execution... using the renamed cmd.exe to run all the commands
ze.docx is a document that exploits the Follina CVE (2022-30190)... xll.xll ... implements code execution via Excel.
KDU uses a vulnerable driver of legitimate software to access arbitrary kernel memory with read/write attributes
Loader will then load the anti-virus driver. When the user is a 64-bit system, it uses the open source KDU (Kernel Driver Utility) to load
adding additional layers of obfuscation and downloaders... All payloads are obfuscated using the Add-PoshObfuscation function.
Hackers can also choose to simulate different bank false security verification interfacs through backdoor control commands, and steal user login credentials
Base64 encrypted and stored the downloaded shellcode. After decryption, it is a Loader written by .Net.
For Windows 10 victims, the script executes MSBuild.exe with a file named dat.xml from the server... Run MSBuild.exe to build an application using an XML stored on a remote server, fetched over SMB.
Upon execution, the LNK file runs the *ammy.dll payload using rundll32.exe... runs it with a renamed rundll32.exe (mmd.exe)
employing multi-layered geo-fencing to ensure infected machines are from those countries only... It checks the geolocation of the link-referred victim against ip-api.com... If the victim isn’t from a targeted country (i.e., Mexico or Brazil) the HTTP connection ends immediately with a 404 message.
including creating a false bank security detection window to trick the user into entering login credentials, thereby stealing the user’s account password.
The banker has a wide set of functionalities, including enumerating and killing processes
The banker searches for indications of its victims being clients of those banks by iterating over the open windows and names of browser tabs, searching for bank names.
employing multi-layered geo-fencing to ensure infected machines are from those countries only... It checks the geolocation of the link-referred victim against ip-api.com... If the victim isn’t from a targeted country (i.e., Mexico or Brazil) the HTTP connection ends immediately with a 404 message.
including creating a false bank security detection window to trick the user into entering login credentials, thereby stealing the user’s account password.
Hackers can control the victim’s machine by issuing the backdoor instructions in the picture, including window control, process management, key logger, clipboard hijacking and other functions.
Hackers can control the victim’s machine by issuing the backdoor instructions in the picture, including window control, process management, key logger, clipboard hijacking and other functions.
33 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Delphi-based banking trojan targeting users in Brazil and Mexico. It replicates interfaces of more than 40 banks to steal 2FA codes and payment card data, can enumerate and kill processes, control keyboard and mouse, manipulate the clipboard, and may install a malicious browser extension or inject rpp.dll. It is delivered through phishing links that generate tailored ZIP/ISO payloads and uses LOLBins such as MSBuild, rundll32, and renamed cmd.exe in multi-stage infection chains.
A banking trojan active in Mexico that is delivered via phishing emails containing malicious LNK files. Clicking the LNK launches PowerShell to download and execute payloads, including a .NET loader and a backdoor. It establishes persistence by replacing winmm.dll, loads an anti-virus bypass driver, supports remote control functions such as process management, keylogging, and clipboard hijacking, and displays fake bank security verification windows to steal online banking credentials.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.