Shylock is a Windows banking trojan first observed in 2011 that targeted online banking users, particularly in the United Kingdom, with additional victimization reported in the United States, Italy, and Turkey. It was designed to steal online banking credentials and facilitate fraudulent transfers from business and personal accounts to attacker-controlled destinations. The malware became notable for combining credential theft with browser-focused compromise techniques intended to take control of the victim’s banking session and support financial fraud.
Shylock used code injection into browser processes to interfere with online banking activity and capture sensitive information. Reported capabilities included improved browser-process injection, evasion measures intended to reduce detection by malware scanners, and a watchdog-style component that helped the malware resist removal and restore its operation after disruption. These traits made it more resilient than many contemporaneous financial malware families and supported persistent access on infected systems long enough to conduct theft.
Victims were commonly infected after interacting with malicious links and executing the downloaded malware. Once installed, Shylock attempted to access funds held in online bank accounts and trick victims into transferring money under attacker control. The malware infected at least tens of thousands of Microsoft Windows systems worldwide before an international law-enforcement and industry operation disrupted its infrastructure in July 2014 by seizing command-and-control servers and taking control of domains used to manage infected machines.
Shylock is widely classified as a banking trojan and financial malware family. Its name is associated with Shakespeare quotations embedded in its code or file properties. The malware is also known in some antivirus naming schemes as Caphaw.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
Disk Spreader can spread the bot via removable drives.
Drive-by URLs with repacked droppers look like this list: The URLs have the following format: https://[random subdomain].[domain]/[DIR]/[DIR-random string]/[dropper file]?r=[random number]
Caphaw has demonstrated an effective technique of obstructing static analysis by encrypting strings such as library names and condition constants using a custom encryption routine and encoding API names using their hashing values.
And every few hours dropper files on the C&C server are repacked by a custom polymorphic cryptor service in order to bypass static detection by antivirus signature.
With a low probability of collision on string name hashes, the API call addresses can easily be retrieved by generating the hash of each API name in the import table and retrieving the API call address when a match is found.
In this version, the Caphaw client was extracted from the .data section of a companion memory injector and written into the memory of explorer.exe.
Otherwise, if the host process is not explorer.exe, userinit.exe or rundll32.exe, it will start to contact the C&C server with the ‘cmd’ value set to ‘ping’ in the message.
Caphaw provides indirect checks for execution under popular virtual machine environments (VMware, VirtualBox and VirtualPC). Caphaw detects virtual machines based on names of active processes and drivers... These tricks make it possible for Capshaw to bypass automated sandbox analysis.
Often identified by its abilities to spread through Skype and inject bank pages... The ‘httpinject’ tag contains the download address of the script file which is to be injected into the web pages.
The report will be encrypted slightly more simply than the other communications and sent back to the server... This contains extended details of the infected host... List of running services
Test 3: (registry value check) Check if any of the following registry entries exist and contain the string ‘VMware’ at ‘SystemProductName’ and ‘SystemManufacturer’.
Besides looking for a sandbox environment, it also scans through every current process to find matches of other anti-virus products.
The malware will also generate a detailed report on the victim’s computer if the client determines that this is the first time the malware has run on the machine.
Caphaw provides indirect checks for execution under popular virtual machine environments (VMware, VirtualBox and VirtualPC). Caphaw detects virtual machines based on names of active processes and drivers... These tricks make it possible for Capshaw to bypass automated sandbox analysis.
After the initial report, it also tries to search for a bitcoin wallet in some known directories and upload it using w=rqt if it finds one.
Often identified by its abilities to spread through Skype and inject bank pages... The ‘httpinject’ tag contains the download address of the script file which is to be injected into the web pages.
Downloaded webinjects take the same form as configuration data... One of the interesting details in the code injected into a bank's web page is the substitution of all phone numbers with fake numbers owned by the attacker.
The video capture and uploader can be used to monitor the victim’s interaction with the computer, therefore drawing an even more complete picture of the target.
Win32/Caphaw is an interesting financial malware family: one of the few that has autoload functionality for automatically stealing money when the user is actively accessing his banking account. An infected user can’t recognize that his money is being stolen, because he sees fake data on the banking web page based on the webinjects' rules.
This comprised the seizure of servers which form the command and control system for the Trojan, as well as taking control of the domains Shylock uses for communication between infected computers.
Dridex has survived through the years by obfuscating its main command-and-control (C&C) servers through proxies.
Backsocks can tunnel the attacker’s traffic through the victim’s machine into its internal networks, which opens up a new area of resources for the attacker to gain access to
Win32/Caphaw has functionality for downloading and executing additional plugins.
The VNC server can enable the attacker to gain remote access to the victim’s computer.
However, Caphaw uses a special technique to hide the active server IPs... on the client side, it generates the full server domains and request URLs by using the hard-coded ones in the following format: [random generated prefix].[hard-coded domain]?r=[random number].
62 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Privately operated banking trojan that stole online banking credentials and induced fraudulent transfers, with modular functionality and a strong UK focus.
Banking trojan targeting online banking systems. It infects Windows computers, communicates with command-and-control infrastructure and malicious domains, and is used to steal funds from business and personal bank accounts.
Financial malware/banking trojan that injects code into browser processes to take control of the victim machine, uses evasion to avoid malware scanners, and includes a watchdog service to resist removal and restore itself.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.