Feodo is a banking Trojan used to steal money from online banking accounts. The provided content states it targeted banks including Bank of America, UBS, and HSBC. Feodo used botnet command-and-control infrastructure, including domains generated via a domain generation algorithm (DGA), to receive operator commands and to drop stolen credentials. Spamhaus reporting cited Feodo botnet domains registered through the Russian registrar NAUNET and described associated infrastructure using FastFlux with hijacked servers. One example of Feodo traffic referenced the domain nolwzyzsqkhjkqhomc.ru communicating over port 8080. The content also notes that Spamhaus identified 63 Feodo command-and-control servers in the first year of its BGP feed reporting. A related indicator source explicitly mentioned in the content is the abuse.ch Feodo IP Blocklist, which is also included in MISP default OSINT feeds.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
The Registrar may terminate the domain name delegation ... should the petition contain information about the domain’s information addressing system being used for: 2. unauthorized access to third parties’ information systems or for infecting these systems with malware or taking control of such software (botnet control);
the majority of botnets still use a basic client-server model, with most relying on HTTP servers to receive commands, many prominent threats now use more advanced infrastructure to evade endpoint blacklisting and be resilient to take-down.
101 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Feodo IP Blocklist - abuse.ch - feed format: csv
An eBanking trojan associated with 63 command-and-control servers identified by Spamhaus.
Banking Trojan used to steal money from online banking accounts. It uses a domain generation algorithm (DGA) to calculate current botnet domains for exfiltrating stolen credentials and receiving commands from botnet operators.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.