The SpyEye banking trojan was reported stealing online banking credentials and enabling fraudulent transactions while victims remained logged in, with newer variants designed to better evade bank fraud controls. Security reporting said the malware mimicked normal user behavior, including navigation patterns and transaction timing, to bypass behavioral detection systems, while also expanding its targeting to more financial institutions in additional countries and growing its command-and-control footprint.
Microsoft described Trojan:Win32/Spyeye as a credential-stealing malware family that captures keystrokes, performs form grabbing, exfiltrates stolen data to remote operators, downloads updates or arbitrary files, and uses rootkit-style techniques to hide its presence. Separate reporting showed SpyEye operators also added a "billinghammer" feature that automated fraudulent online purchases with stolen payment card data, routing transactions through infected machines near cardholders to reduce fraud alerts and turning compromised hosts into infrastructure for broader financial crime.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
Microsoft documented Trojan:Win32/Spyeye as a credential-stealing trojan that captures keystrokes, performs form grabbing, exfiltrates data, downloads files, and uses rootkit techniques and API hooking to evade detection. The description also noted persistence via a Run registry key and that antivirus alerts may be the only visible symptom of infection.
Roman Hüssy of SpyEye Tracker said there were only about 20 active SpyEye command-and-control servers in May. This served as a baseline before later reported growth in the malware's infrastructure.
In April, authorities charged a 26-year-old Lithuanian and a 45-year-old Latvian for allegedly using SpyEye. The charges included conspiracy to cause unauthorized computer modifications, conspiracy to defraud, and concealing proceeds from crime; a third 26-year-old man was bailed pending further questioning.
SpyEye botnet kit added a module called "billinghammer" that automates fraudulent software purchases using stolen payment card data from infected victims. The feature was designed to help botmasters monetize stolen cards while evading anti-fraud checks by routing transactions through infected machines near the cardholder's location.
SpyEye Tracker reported that about 46 SpyEye command-and-control servers were online as of Tuesday, up from roughly 20 in May. Roman Hüssy said the increase showed SpyEye was growing significantly.
Trusteer reported that newer SpyEye versions included code intended to mimic normal banking-user behavior and evade banks' behavioral fraud-detection systems. The company also said SpyEye had expanded the number of financial institutions and countries it could target, indicating broader adoption by criminal groups.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
computerworld.com
Open sourcemicrosoft.com
Open sourcekrebsonsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.