Monday, April 28, 2025
HomeComputer SecurityNew Banking Malware Steal Money From Victim's Bank Accounts Using Weaponized Adobe...

New Banking Malware Steal Money From Victim’s Bank Accounts Using Weaponized Adobe Reader

Published on

SIEM as a Service

Follow Us on Google News

Newly discovered banking malware steal money from targeted victims bank accounts that distributed via malicious Adobe Reader.

A researcher discovered more than 300 unique samples which are used by 200 servers to compromise and steal money from victims bank account especially from  Brazilian credit institutions clients.

This Malware’s unique capability and evasion technique trying to find out whether the injected system has run under a virtual environment, if yes then it automatically terminates itself.

- Advertisement - Google News

Also, it keeps monitoring the victims Windows local language settings and finds out the Portuguese language in order to avoid infection.

Dr.Web researchers named this malware as  Trojan.PWS.Banker1.28321 and it launch with the name of adobe reader.

Banking Malware Infection Process

The initial infection started by dropping malicious adobe reader applications into victims machine which later drops the VBscript scripts since the malware is written in .NET.

Once the infected users execute the malware then the load script is dropped by standard MSScriptControl.ScriptControl COM object.

Later it connects to attackers command & control server and downloads two ZIP-archives from it.

According to Dr. Web Research, One file contains the obfuscated dynamic library created using Delphi development environment. This library contains the malicious program’s main functions.

After the complete infection, Once the victims open the Internet banking sites of various Brazilian financial institutions such as Santander, Diagnostico BB, Sicredi, etc then it will replace the original web page with malicious fake authentication form.

Finally malware requests to enter an authorization verification code that received from banks then it will send to the attackers.

This scheme of replacing the content of original, user-viewed web pages with the “bank-client” systems is used by many banking Trojans. Often they threaten credit institutions’ clients not only in Brazil but around the world, Dr. Web Said.

Also Read:

Beware!! New Android Malware That Can Read Your WhatsApp Messages & Take Screen Shots

APT Group Uses Dangerous LoJax Malware That Can Survive After OS Re-installation and Hard Disk Replacement

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

How To Use Digital Forensics To Strengthen Your Organization’s Cybersecurity Posture

Digital forensics has become a cornerstone of modern cybersecurity strategies, moving beyond its traditional...

Building A Strong Compliance Framework: A CISO’s Guide To Meeting Regulatory Requirements

In the current digital landscape, Chief Information Security Officers (CISOs) are under mounting pressure...

Two Systemic Jailbreaks Uncovered, Exposing Widespread Vulnerabilities in Generative AI Models

Two significant security vulnerabilities in generative AI systems have been discovered, allowing attackers to...

New AI-Generated ‘TikDocs’ Exploits Trust in the Medical Profession to Drive Sales

AI-generated medical scams across TikTok and Instagram, where deepfake avatars pose as healthcare professionals...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

North Korean APT Hackers Pose as Companies to Spread Malware to Job Seekers

Silent Push Threat Analysts have uncovered a chilling new cyberattack campaign orchestrated by the...

Russian VPS Servers With RDP and Proxy Servers Enable North Korean Cybercrime Operations

Trend Research has uncovered a sophisticated network of cybercrime operations linked to North Korea,...

New Malware Hijacks Docker Images Using Unique Obfuscation Technique

A recently uncovered malware campaign targeting Docker, one of the most frequently attacked services...