Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
The library names are obfuscated with XOR and a hardcoded key... The reply from the C2 server will be a hex string that will be used as an XOR key to obfuscate further C2 communications.
After things are setup, an svchost (-k netsvcs) process is started and a DLL is injected into it... once it receives a PID it will inject the “engine” component into that process.
It will then perform three types of anti-analysis: Detecting common analysis software such as IDA Pro and Sysinternals tools Detecting common sandbox and virtual machines Detecting debugging via a timing check If it detects it is being run in an analysis environment it will delete itself.
These hooks monitor the victim’s web browsing (HTTPS doesn’t matter at this layer of communications) and continuously compares traffic to its list of webinjects. If a match is found the malicious webinject code is injected in the webpage, the modified web page is shown to the victim, and credential theft can happen.
Before transitioning to the next component some system information is written to a “<botid>.txt” text file... The system information is pipe delimited and consists of: info Windows version Computer name Username isWow64 status is Admin status
It will then perform three types of anti-analysis: Detecting common analysis software such as IDA Pro and Sysinternals tools Detecting common sandbox and virtual machines Detecting debugging via a timing check If it detects it is being run in an analysis environment it will delete itself.
These hooks monitor the victim’s web browsing (HTTPS doesn’t matter at this layer of communications) and continuously compares traffic to its list of webinjects. If a match is found the malicious webinject code is injected in the webpage, the modified web page is shown to the victim, and credential theft can happen.
It also phones home to a command and control (C2) server... After this initial setup an empty HTTP POST request is sent to the C2 server... Commands are polled with a “ping” command.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Banking malware with a dropper, bot, and webinject/Man-in-the-Browser components. It establishes persistence, injects into svchost and browsers, communicates with a C2 server, supports download-and-execute, VNC, SOCKS4 proxy, self-update, and steals credentials by injecting malicious content into targeted banking and other websites.
Mentioned only as a comparison point for how Matrix Banker might evolve.
A banking trojan designed to steal banking credentials from victims. The article ties it to the accused sextortion scam mastermind and notes its source code was released publicly, enabling reuse by other criminals.
A banking trojan authored by one of the charged individuals; the content also notes its source code was released after it appeared for sale on cybercrime forums.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.