The Retefe banking Trojan was used in phishing campaigns targeting organizations in Sweden, Switzerland, and Japan, where it intercepted online banking sessions by installing a rogue root certificate and changing proxy settings to route traffic through attacker-controlled infrastructure. Rather than relying on traditional browser hooking alone, the malware used PowerShell to enable man-in-the-middle interception of financial traffic, and infections also deployed Smoke Loader as a secondary payload for credential theft and additional malware delivery.
Technical analysis of later Retefe variants showed the malware’s embedded JavaScript payload was hidden in the PE file’s .data segment and decoded with a 4-byte XOR key derived from the script length and arithmetic operations. Researchers documented an unpacking workflow that used YARA to locate decoding parameters, calculate the buffer RVA, derive the XOR array, and recover the script, highlighting how the malware’s packing and storage methods evolved from earlier variants while preserving its banking-focused intrusion model.

See the actors and campaigns active against you right now.
5 events from the most recent confirmed update back to the earliest known activity.
A technical writeup published on 2018-12-28 explained how to statically unpack current Retefe banking malware samples using YARA-derived parameters to locate, extract, and decode the embedded script. The author also released source code for the unpacker and confirmed it worked on three listed sample hashes.
A prior post titled "Reversing Retefe" documented a Retefe variant that protected its payload with a one-byte XOR key. The later unpacker writeup cites this as evidence of an earlier implementation before subsequent code changes.
The 2018 unpacker writeup states that contemporary Retefe samples stored their JavaScript payload in the .data segment and decoded it with a 4-byte XOR key derived from the script length and mathematical operations. The author inferred the threat actor had changed its code base from the variant described in the November 2018 reversing post.
The 2015 research detailed that Retefe used PowerShell to install a rogue root certificate and change proxy settings so traffic to targeted banks was routed through attacker-controlled infrastructure for man-in-the-middle interception. The same campaign also downloaded Smoke Loader as additional malware.
Palo Alto Networks reported a recent two-week surge of phishing emails delivering the Retefe banking Trojan to organizations in Western Europe and Japan. The campaign used localized order and receipt lures and targeted banking users in Sweden, Switzerland, and Japan.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
5 references tracked. Mallory keeps watching after this page renders.
govcert.admin.ch
Open sourcegithub.com
Open sourcegithub.com
Open sourceresearchcenter.paloaltonetworks.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.