Shylock, also known as Caphaw, is a Windows banking trojan and botnet malware family active since 2011 and primarily associated with online banking fraud against financial institutions in Europe and North America. It is known for man-in-the-browser functionality, browser API hooking, webinjects, and automated transaction theft while victims are actively using online banking sessions. The malware has targeted major banks and has been especially active in the United Kingdom, Italy, Denmark, and Turkey.
Shylock is designed for stealth and resilience. It injects into legitimate processes, including Windows shell and browser processes, and uses inter-process communication to coordinate components. It employs anti-analysis measures such as anti-VM, anti-debugging, encrypted strings, API resolution by hash, and sandbox checks that can cause the malware to terminate or remove itself in analysis environments. It has also used encrypted command-and-control communications over SSL with RC4-protected data and domain-generation techniques to make infrastructure disruption more difficult.
On infected systems, Shylock performs extensive host profiling, collecting system, user, browser, process, service, privilege, and security-product information. It establishes persistence through autorun mechanisms and can modify browser- and Internet-related settings. Its core banking-theft capability relies on inline hooking and HTTP injection in browsers such as Internet Explorer and Firefox, allowing it to manipulate banking sessions, steal credentials, alter page content, substitute contact information shown to victims, and conceal fraudulent transactions.
Shylock evolved into a modular platform with downloadable plug-ins that expanded its functionality beyond banking theft. Documented modules have included browser and Flash cookie theft, FTP credential theft, remote desktop access through VNC, SOCKS proxying, video capture, Skype-based propagation, spreading through shared folders and removable media, and theft of cryptocurrency wallet files. Some variants also deployed a rootkit or MBR bootkit component to improve persistence and concealment.
Initial infection has been linked in some campaigns to exploit-kit delivery against vulnerable Java installations, although not every intrusion vector has been conclusively established. Overall, Shylock is best characterized as a mature, modular financial malware platform combining credential theft, session manipulation, persistence, propagation, and defense evasion to support fraud and broader post-compromise activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
Caphaw avoids local detection by injecting itself into legitimate processes such as explorer.exe or iexplore.exe... Further evidence of this being Caphaw exists in the banking information that it is listening for once it is injected into key Windows Processes.
Caphaw has demonstrated an effective technique of obstructing static analysis by encrypting strings such as library names and condition constants using a custom encryption routine and encoding API names using their hashing values.
With a low probability of collision on string name hashes, the API call addresses can easily be retrieved by generating the hash of each API name in the import table and retrieving the API call address when a match is found.
A binary executable (.exe) file is created in the attack sequence and masquerades as a .php file.
Caphaw avoids local detection by injecting itself into legitimate processes such as explorer.exe or iexplore.exe... Further evidence of this being Caphaw exists in the banking information that it is listening for once it is injected into key Windows Processes.
The malware then augments system processes to hinder its removal... WriteProcessMemory ... C:\WINDOWS\explorer.exe ... CreateThread
Otherwise, if the host process is not explorer.exe, userinit.exe or rundll32.exe, it will start to contact the C&C server with the ‘cmd’ value set to ‘ping’ in the message.
The report will be encrypted slightly more simply than the other communications and sent back to the server... This contains extended details of the infected host... List of running services
Test 3: (registry value check) Check if any of the following registry entries exist and contain the string ‘VMware’ at ‘SystemProductName’ and ‘SystemManufacturer’.
Besides looking for a sandbox environment, it also scans through every current process to find matches of other anti-virus products.
The malware will also generate a detailed report on the victim’s computer if the client determines that this is the first time the malware has run on the machine.
The malware executable checks to see if it is running in a VM environment and also ensures that the host on which it is installed is connected to the Internet (failing which it will not run).
After the initial report, it also tries to search for a bitcoin wallet in some known directories and upload it using w=rqt if it finds one.
we found the following 24 major banks' sites were actively being monitored by the infection primarily to seek out the victim's online banking credentials.
The video capture and uploader can be used to monitor the victim’s interaction with the computer, therefore drawing an even more complete picture of the target.
These can be used to identify the malware's command and control (CnC) servers so that the infected hosts can 'dial home' and receive/send commands/data.
All of the communication traffic goes through C&C server port 443 using the SSL protocol.
Backsocks can tunnel the attacker’s traffic through the victim’s machine into its internal networks, which opens up a new area of resources for the attacker to gain access to
Some other capabilities, such as VNC and archiver, could be downloaded from the Internet later, after the configuration files enabled them.
The VNC server can enable the attacker to gain remote access to the victim’s computer.
The Caphaw avoids local detection by injecting itself into legitimate processes such as explorer.exe or iexplore.exe, while simultaneously obfuscating its phone home traffic through the use of Domain Generated Algorithm created addresses using Self Signed SSL certificates.
34 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modular botnet/banking trojan with man-in-the-browser capabilities that injects into browser processes, steals banking information, communicates with C2 over SSL/RC4, performs anti-VM and anti-debug checks, and can download plug-ins such as VNC, cookie stealers, disk spreaders, message spreaders, and proxy/backsocks components.
Banking malware targeting major European banks. It uses webinjects, process injection, IPC via named pipes, anti-VM checks, polymorphic droppers, downloadable plugins, and can automatically steal money during active online banking sessions while showing fake data to the victim.
Banking trojan focused on stealing online banking credentials. It injects into legitimate processes such as explorer.exe and iexplore.exe, uses DGA-generated domains and self-signed SSL for C2 communications, performs geo-location checks, establishes persistence via registry autoruns, checks for VM/Internet connectivity, and monitors banking sites to capture victim credentials.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.