Researchers documented Caphaw (also known as Shylock) as a banking trojan that evolved into a mature botnet platform capable of credential theft, browser injection, and broader post-compromise activity. Active since 2011, the malware targeted online banking users at at least 24 financial institutions, primarily in Europe with some U.S. banks also affected. Analysts linked infections to likely exploit-kit delivery against vulnerable Java installations and found the malware establishing persistence through registry autorun entries, modifying Internet Explorer settings, and injecting into processes such as explorer.exe, iexplore.exe, and other browsers to monitor sessions and steal credentials through man-in-the-browser techniques.
Technical analysis showed Caphaw using layered evasion and resilient command-and-control methods, including anti-VM, anti-debugging, domain generation algorithms, and RC4-encrypted traffic over SSL with self-signed certificates. Its plug-in architecture enabled operators to extend functionality beyond banking theft to include VNC access, Skype and disk spreading, cookie theft, and SOCKS proxying, while host reconnaissance and code injection made removal more difficult. Researchers assessed the malware as a dangerous, long-lived threat because it combined financial fraud with modular capabilities suited for deeper network infiltration and persistent botnet operations.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
Fortinet's analysis says version 1.7.x marked a period of structural stability for Caphaw beginning in February 2013. The malware had matured from its earlier builds into a more stable platform by that point.
Fortinet researchers reported that their team first received a sample of the Caphaw malware family, also known as Shylock, in late October 2011. This marks the earliest explicitly anchored event in the references.
The references state that Caphaw has targeted users' bank accounts since 2011 and operated as a persistent botnet malware family from that year. This establishes the start of the malware family's observed activity.
Zscaler ThreatLabZ reported a recent increase in Caphaw infections over the prior month, tying the activity to credential monitoring at 24 financial institutions, mainly in Europe with some U.S. banks also affected. The report also noted low antivirus detection and suspected exploit-kit delivery via vulnerable Java installations.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 34 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
abuse.ch
Open sourcevirusbulletin.com
Open sourcezscaler.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.