Researchers detailed how Win32/Theola abuses a malicious Google Chrome plugin to conduct banking fraud, using legitimate Chrome and NPAPI functionality to manipulate web sessions, intercept sensitive information, and evade common detection methods. The malware was identified as a component of the Win32/Mebroot.FX bootkit and communicates with other malware modules through named pipes, allowing it to coordinate credential theft without relying on more visible user-mode network hooks.
The plugin alters web form handling to expose password fields and capture submitted banking data, and it also includes video recording capability through the x264 library to monitor victim activity. Reported detections rose sharply in early 2013, with infections concentrated in countries including the Netherlands, Norway, Italy, Denmark, and the Czech Republic, indicating a targeted campaign aimed at online banking users.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
The article states that detections of Theola plugins increased from the end of January 2013. The Netherlands, Norway, Italy, Denmark, and the Czech Republic were among the most affected countries.
The Win32/Mebroot.FX bootkit family, of which Theola is described as a component, had been known since 2007.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.