Proofpoint reported a renewed Retefe banking Trojan campaign targeting online banking users in Switzerland, Germany, and Liechtenstein, with operators shifting tactics to improve stealth and credential theft. Rather than relying mainly on web injects, Retefe redirected victim banking traffic through a proxy, and in one observed Switzerland-focused campaign an OLE-based lure document delivered Smoke Loader, which then fetched the banking malware. Researchers also noted infrastructure and tooling changes, including the replacement of Tor with stunnel for encrypted tunneling and the use of a shareware application, Convert PDF to Word Plus 1.0, in the infection chain.
The campaign also expanded its reach to macOS users by distributing fake Adobe installer applications signed with a developer certificate, a technique designed to help the malware pass Apple Gatekeeper checks and appear trustworthy when opened on a Mac. The activity showed that Retefe operators were actively refining cross-platform delivery, downloader selection, and trust-abuse methods to sustain banking credential theft against regional financial institutions and their customers.

See the actors and campaigns active against you right now.
4 events from the most recent confirmed update back to the earliest known activity.
On 2019-04-17, Proofpoint observed a geographically targeted Retefe campaign against Switzerland. The lure document used an OLE package to deliver Smoke Loader, which later downloaded Retefe.
The report states that Retefe returned to more regular attacks against Swiss and German victims in April 2019. This resurgence included operational changes such as using stunnel instead of Tor and Smoke Loader instead of sLoad.
In March 2019, Proofpoint researchers identified an abused "Convert PDF to Word Plus 1.0" installer in a public malware repository. The backdoored application was later described as part of Retefe's 2019 infection chain.
The report says Retefe campaigns targeting macOS continued through the first several months of 2019. These campaigns used fake Adobe installer applications signed with developer certificates to help bypass Gatekeeper protections.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 90 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.