Research presented at PHDays detailed how banking malware undermined smartcard-based protections in remote banking systems by attacking the infected endpoint rather than the card itself. ESET highlighted Win32/Spy.Ranbyus, which can detect connected smartcard devices and relay attacker-issued APDU commands through its command-and-control channel, allowing remote manipulation of the card from an already compromised machine.
The report also described RDPdoor v4.2.x, linked to the Carberp cybercrime group, which profiles smartcard devices and can enable remote smartcard access for fraud operations. The findings showed that smartcards can be effectively bypassed when malware operates at the SmartCard API layer on a victim system, and ESET noted related infection activity spread through blackhat SEO poisoning and Nuclear Pack exploits tied to Russian Google search results for Eurovision-themed queries.

See the actors and campaigns active against you right now.
4 events from the most recent confirmed update back to the earliest known activity.
Aleksandr Matrosov and Eugene Rodionov presented “Smartcard vulnerabilities in modern banking malware” at the PHDays 2012 conference in Russia. Their research detailed how banking malware such as Win32/Spy.Ranbyus and RDPdoor abused smartcards through the SmartCard API layer.
Researchers observed blackhat SEO poisoning in Russian Google search results for Eurovision 2012 queries. Victims were redirected to a fake Eurovision site and then potentially to the Nuclear Pack exploit service.
At the beginning of 2012, the Carberp cybercrime group was observed using RDPdoor v4.2.x. The malware profiled infected systems and smartcard devices used in Russian remote banking systems so operators could later deploy additional modules.
A 2010 blog post titled “Dr. Zeus: the Bot in the Hat” previously described malware that manipulated APDU commands and used hidden remote channels to control a smartcard device. The 2012 article cites this as prior documentation of the technique.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.