Trusted Design

Banking Trojan Attempts To Steal Brazillion$

概要

Banking trojans are among some of the biggest threats to everyday users as they directly impact the user in terms of financial loss. Talos recently observed a new campaign specific to South America, namely Brazil. This campaign was focused on various South American banks in an attempt to steal credentials from the user to allow for illicit financial gain for the malicious actors. The campaign Talos analysed focused on Brazilian users and also attempted to remain stealthy by using multiple methods of re-direction in an attempt to infect the victim machine. It also used multiple anti-analysis techniques and the final payload was written in Delphi which is quite unique to the banking trojan landscape.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

FIN7

Score: 14.89
Matched TTPs:
  • T1674 - Input Injection
  • T1036.004 - Masquerade Task or Service
  • T1195.002 - Compromise Software Supply Chain
  • T1564.001 - Hidden Files and Directories
  • T1078.003 - Local Accounts
MITREへのリンク →

APT29

Score: 8.56
Matched TTPs:
  • T1550.003 - Pass the Ticket
  • T1027.002 - Software Packing
  • T1078.003 - Local Accounts
MITREへのリンク →

APT32

Score: 14.02
Matched TTPs:
  • T1550.003 - Pass the Ticket
  • T1036.004 - Masquerade Task or Service
  • T1218.010 - Regsvr32
  • T1564.001 - Hidden Files and Directories
  • T1078.003 - Local Accounts
MITREへのリンク →

BRONZE BUTLER

Score: 3.84
Matched TTPs:
  • T1550.003 - Pass the Ticket
MITREへのリンク →

Kimsuky

Score: 19.37
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1657 - Financial Theft
  • T1218.010 - Regsvr32
  • T1027.002 - Software Packing
  • T1588.003 - Code Signing Certificates
  • T1588.005 - Exploits
  • T1078.003 - Local Accounts
MITREへのリンク →

FIN13

Score: 11.82
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1657 - Financial Theft
  • T1565 - Data Manipulation
  • T1564.001 - Hidden Files and Directories
MITREへのリンク →

Wizard Spider

Score: 8.87
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1555.004 - Windows Credential Manager
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

PROMETHIUM

Score: 4.76
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1078.003 - Local Accounts
MITREへのリンク →

ZIRCONIUM

Score: 4.15
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1027.002 - Software Packing
MITREへのリンク →

Lazarus Group

Score: 8.89
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1027.007 - Dynamic API Resolution
  • T1564.001 - Hidden Files and Directories
MITREへのリンク →

Storm-0501

Score: 9.42
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1657 - Financial Theft
  • T1218.010 - Regsvr32
  • T1027.002 - Software Packing
MITREへのリンク →

APT41

Score: 7.08
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1195.002 - Compromise Software Supply Chain
  • T1027.002 - Software Packing
MITREへのリンク →

Scattered Spider

Score: 7.06
Matched TTPs:
  • T1657 - Financial Theft
  • T1538 - Cloud Service Dashboard
MITREへのリンク →

Medusa Group

Score: 9.11
Matched TTPs:
  • T1657 - Financial Theft
  • T1027.002 - Software Packing
  • T1218.014 - MMC
MITREへのリンク →

Play

Score: 5.19
Matched TTPs:
  • T1657 - Financial Theft
  • T1078.003 - Local Accounts
MITREへのリンク →

Mustang Panda

Score: 14.49
Matched TTPs:
  • T1678 - Delay Execution
  • T1588.003 - Code Signing Certificates
  • T1027.007 - Dynamic API Resolution
  • T1564.001 - Hidden Files and Directories
MITREへのリンク →

Cobalt Group

Score: 5.67
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1195.002 - Compromise Software Supply Chain
MITREへのリンク →

Threat Group-3390

Score: 8.13
Matched TTPs:
  • T1195.002 - Compromise Software Supply Chain
  • T1027.002 - Software Packing
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

SideCopy

Score: 4.13
Matched TTPs:
  • T1614 - System Location Discovery
MITREへのリンク →

Volt Typhoon

Score: 6.19
Matched TTPs:
  • T1614 - System Location Discovery
  • T1027.002 - Software Packing
MITREへのリンク →

OilRig

Score: 6.77
Matched TTPs:
  • T1555.004 - Windows Credential Manager
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

Stealth Falcon

Score: 3.62
Matched TTPs:
  • T1555.004 - Windows Credential Manager
MITREへのリンク →

Turla

Score: 6.29
Matched TTPs:
  • T1555.004 - Windows Credential Manager
  • T1078.003 - Local Accounts
MITREへのリンク →

Rocke

Score: 4.72
Matched TTPs:
  • T1027.002 - Software Packing
  • T1564.001 - Hidden Files and Directories
MITREへのリンク →

Equation

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

Strider

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

BlackTech

Score: 3.15
Matched TTPs:
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

FIN8

Score: 3.15
Matched TTPs:
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

APT28

Score: 6.80
Matched TTPs:
  • T1564.001 - Hidden Files and Directories
  • T1550.001 - Application Access Token
MITREへのリンク →

Tropic Trooper

Score: 5.33
Matched TTPs:
  • T1564.001 - Hidden Files and Directories
  • T1078.003 - Local Accounts
MITREへのリンク →

HAFNIUM

Score: 9.46
Matched TTPs:
  • T1564.001 - Hidden Files and Directories
  • T1550.001 - Application Access Token
  • T1078.003 - Local Accounts
MITREへのリンク →

Axiom

Score: 4.54
Matched TTPs:
  • T1001.002 - Steganography
MITREへのリンク →

Ember Bear

Score: 4.13
Matched TTPs:
  • T1588.005 - Exploits
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Kimsuky

Score: 0.78
Matched TTPs:
  • T1588.005 - Exploits
  • T1657 - Financial Theft
  • T1078.003 - Local Accounts
  • T1027.002 - Software Packing
  • T1218.010 - Regsvr32
  • T1588.003 - Code Signing Certificates
  • T1036.004 - Masquerade Task or Service
MITREへのリンク →

FIN7

Score: 0.71
Matched TTPs:
  • T1195.002 - Compromise Software Supply Chain
  • T1564.001 - Hidden Files and Directories
  • T1078.003 - Local Accounts
  • T1674 - Input Injection
  • T1036.004 - Masquerade Task or Service
MITREへのリンク →

Mustang Panda

Score: 0.64
Matched TTPs:
  • T1564.001 - Hidden Files and Directories
  • T1588.003 - Code Signing Certificates
  • T1027.007 - Dynamic API Resolution
  • T1678 - Delay Execution
MITREへのリンク →

APT32

Score: 0.62
Matched TTPs:
  • T1550.003 - Pass the Ticket
  • T1078.003 - Local Accounts
  • T1218.010 - Regsvr32
  • T1564.001 - Hidden Files and Directories
  • T1036.004 - Masquerade Task or Service
MITREへのリンク →

FIN13

Score: 0.59
Matched TTPs:
  • T1564.001 - Hidden Files and Directories
  • T1657 - Financial Theft
  • T1565 - Data Manipulation
  • T1036.004 - Masquerade Task or Service
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る