Proofpoint reported that UrlZone and Vawtrak banking Trojan campaigns expanded into Japan, with additional UrlZone activity also targeting Spain. UrlZone was distributed through large-scale spam operations, while Vawtrak infections were delivered through the Angler Exploit Kit. The campaigns targeted numerous Japanese banks and several Spanish institutions, signaling a move beyond the more frequently targeted UK and US banking sectors.
Researchers found both malware families used the same dynamic web-inject framework to alter banking sessions and steal credentials, PINs, and one-time passwords, indicating either shared operators or a rented third-party service. Proofpoint also linked the UrlZone spam chain to a broader affiliate ecosystem involving Andromeda, Pushdo, Neutrino Bot (also known as MS:Win32/Kasidet), and Pony, while separate analysis described Neutrino as a multifunctional botnet malware with keylogging, file theft, command execution, persistence, and DDoS capabilities that had previously appeared in exploit-kit-driven infection chains.

See the actors and campaigns active against you right now.
6 events from the most recent confirmed update back to the earliest known activity.
Proofpoint observed the Angler Exploit Kit delivering Vawtrak ID 28 to Japanese users on February 2, 2016. The campaign targeted numerous Japanese banking domains.
In January and February 2016, Proofpoint observed banking Trojan campaigns expanding into Japan and Spain, with UrlZone spread by spam and Vawtrak by Angler EK. Analysis showed both malware families used the same dynamic web-inject system to steal credentials, PINs, and one-time passwords, suggesting shared resources or a rented third-party capability.
On January 27, 2016, Proofpoint observed a Cryptowall campaign that downloaded the same Neutrino Bot seen in the UrlZone activity. Proofpoint assessed this overlap suggested shared affiliates or spamming partners across the campaigns.
Proofpoint observed a large spam campaign on January 21, 2016 sending tens of thousands of emails to Japanese accounts with the subject line "copy 3" and zipped executables. The attachment delivered Andromeda, which primarily downloaded UrlZone and also led to Pushdo, Neutrino Bot, and Pony in the infection chain.
Proofpoint observed an email campaign on December 11, 2015 delivering the Andromeda botnet. In that earlier campaign, Andromeda downloaded Pushdo but not the fuller UrlZone-related chain seen later.
The actor "n3utrino" was advertising Neutrino Bot on underground forums, presenting it as an "HTTP stress testing tool" while offering broader botnet capabilities and pricing details. The advertising activity is explicitly described as ongoing since December 2013.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 67 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
fireeye.com
Open sourceproofpoint.com
Open sourcemalware.dontneedcoffee.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.