Hesperbot is a modular banking trojan first identified in 2013 and used against online banking customers in Turkey, the Czech Republic, Portugal, and the United Kingdom. It is a distinct malware family rather than a Zeus or SpyEye variant, although it adopts techniques common to earlier banking malware. The threat is designed primarily for financial theft through credential interception, browser manipulation, and abuse of multi-factor authentication workflows.
The malware is delivered through phishing-style campaigns that impersonate trusted organizations and distribute executable payloads disguised as invoices, parcel notices, or similar documents, often using double-extension filenames. On Windows, Hesperbot uses a dropper, a core module, and multiple plug-ins. The dropper injects the core component into a user process, while the core establishes persistence, communicates with command-and-control infrastructure, and retrieves configuration data, plug-ins, updates, and additional executables.
Hesperbot is notable for its extensive browser-focused interception capabilities. It hooks network and browser-related functions to intercept HTTP and HTTPS traffic through a local man-in-the-middle proxy, suppresses certificate warnings, and targets a broad set of browsers. Its modules support form grabbing, keylogging, screenshots, video capture, and HTML injection. Web injects are used to alter banking sessions in real time, steal credentials, and present fraudulent prompts to victims.
A prominent feature of Hesperbot is its hidden VNC capability, which creates a concealed remote desktop session that allows operators to interact with the victim environment without disrupting the visible user session. This enables direct abuse of authenticated banking sessions and access to browser-associated data such as cookies and active sessions.
Hesperbot also extended attacks to mobile devices by using web injects to trick victims into installing companion malware on Android, Symbian, and BlackBerry phones. These mobile components were used to intercept and forward SMS messages, enabling theft of one-time authentication codes used in banking transactions. The mobile malware also supported SMS-based remote control.
Observed campaigns and configuration data indicate a strong focus on online banking fraud rather than broad credential harvesting. Confirmed victim losses were reported, particularly in the Czech Republic, and infections were observed at meaningful scale in Turkey. Comments found in injection scripts suggest Russian-speaking operators or developers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Furthermore, an undocumented trick of hooking UserNotifyProcessCreate is used when running inside csrss.exe, to ensure that the trojan’s code will be injected into every new process.
The dropper’s role is to inject the main component – ‘core’ – into explorer.exe.
the downloaded data (namely the configuration file and plugin modules) is encrypted using the Twofish cipher.
The keylogger module intercepts key strokes by hooking the functions GetMessage and TranslateMessage in user32.dll.
If the configuration file specifies that the current URL should be monitored, the data is written to a log.
the malicious module also hooks functions responsible for certificate verification.
For storing the downloaded data as well as other auxiliary binaries (e.g. the log created by the keylogger module), Hesperbot uses a randomly named subdirectory under %APPDATA%.
The keylogger module intercepts key strokes by hooking the functions GetMessage and TranslateMessage in user32.dll.
If the configuration file specifies that the current URL should be monitored, the data is written to a log.
screenshots and video capture is done by the httpi module, if specified in the configuration file.
The video capture functionality has been used by the Zeus banking trojan spin-off Citadel and provides the attackers with an even better overview of what’s happening on the victim’s screen.
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only for code similarity: Wild Neutron's HTTPS proxy module is said to be practically identical to one used by Hesperbot.
Mentioned as another potentially related banking trojan whose operators may have collaborated or shared tooling with Pinkslipbot-linked infrastructure.
A modular banking trojan targeting online banking users. It performs keylogging, screenshots, video capture, form grabbing, HTML/web injects, HTTPS traffic interception via a local man-in-the-middle proxy, hidden VNC access, SOCKS proxying, and uses mobile components on Android, Symbian, and Blackberry to intercept SMS/mTAN messages for banking fraud.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.