Thursday, May 8, 2025
HomeComputer SecurityOrganized Cybercrime - Hacker Groups Work Together To Distribute Banking Malware Globally

Organized Cybercrime – Hacker Groups Work Together To Distribute Banking Malware Globally

Published on

SIEM as a Service

Follow Us on Google News

The banking malware considered a top threat, it allows a malware developer an easy way to gain access to someone and cause serious damage.

According to the reports, the cybercrime costs more than $600 billion in 2017 and for 2018 predicted $1.5 trillion in losses.

Hacker groups continue to exchange their scripts, tactics, and techniques to bypass the security measures and to evade from law enforcement agencies.

- Advertisement - Google News

The most popular active banking malware are TrickBot, cedID, Gozi, Ramnit and Zesus panda. According to the IBM report, the hacker groups have ties to each other to fuel their financial crime economy.

“The banking Trojan arena is dominated by groups from the same part of the world, by people who know each other and collaborate to orchestrate high-volume wire fraud,” IBM Executive Security Advisor, Limor Kessem.

Active Banking Malware

Trickbot is the infamous banking malware which steals login credentials from applications, it was discovered long back ago and it is the most aggressive trojan of 2018.

At earlier stages, Trickbot appears not connected with any trojans, in the recent campaign, the Trickbot drops IcedID. In another campaign observed by ESET Emotet drops TrickBot and IcedId.

“By August 2018, our researchers noted that IcedID had been upgraded to behave in a similar way to the TrickBot Trojan in terms of its deployment,” Kessem added.

In another Trickbot campaign, it drops the Ryuk Ransomware and Emotet malware. The Ryuk Ransomware infects the system and demands ransom.

The 2019 version of Trickbot variant adds three new functions Virtual Network Computing (VNC), PuTTY and Remote Desktop Protocol (RDP) platforms.

Gozi, yet another highly active malware which was first spotted in 2007, it was constantly evolving and its source code leak gives rise to a number of active trojans today. The Gozi malware is distributed through macro-enabled spreadsheet attachments.

Ramnit another banking trojan, which is initially a self-replicating worm evolved modular banking Trojan, later in 2018 it code was revamped partnering with Ngioweb.

Based on IBM research, “starting from 2018 connected the major cybercrime gangs together in explicit collaboration. This trend is a negative sign that highlights how botnet operators join forces, revealing the resilience factor in these nefarious operations.”

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Top Ransomware Groups Target Financial Sector, 406 Incidents Revealed

Flashpoint analysts have reported that between April 2024 and April 2025, the financial sector...

Agenda Ransomware Group Enhances Tactics with SmokeLoader and NETXLOADER

The Agenda ransomware group, also known as Qilin, has been reported to intensify its...

SpyCloud Analysis Reveals 94% of Fortune 50 Companies Have Employee Data Exposed in Phishing Attacks

SpyCloud, the leading identity threat protection company, today released an analysis of nearly 6...

PoC Tool Released to Detect Servers Affected by Critical Apache Parquet Vulnerability

F5 Labs has released a new proof-of-concept (PoC) tool designed to help organizations detect...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Top Ransomware Groups Target Financial Sector, 406 Incidents Revealed

Flashpoint analysts have reported that between April 2024 and April 2025, the financial sector...

Agenda Ransomware Group Enhances Tactics with SmokeLoader and NETXLOADER

The Agenda ransomware group, also known as Qilin, has been reported to intensify its...

PoC Tool Released to Detect Servers Affected by Critical Apache Parquet Vulnerability

F5 Labs has released a new proof-of-concept (PoC) tool designed to help organizations detect...