Remove google-cloud-run-banking-trojan-operation
article thumbnail

Google Cloud Run Abused in Massive Banking Trojan Operation

Heimadal Security

Researchers in security are issuing warnings about threat actors misusing Google Cloud Run to spread large amounts of banking trojans, such as Astaroth, Mekotio, and Ousaban. Reports from […] The post Google Cloud Run Abused in Massive Banking Trojan Operation appeared first on Heimdal Security Blog.

Banking 100
article thumbnail

Trojan Lampion is back after 3 months

Security Affairs

Trojan Lampion is back after 3 months. Trojan Lampion is a malware observed at the end of the year 2019 impacting Portuguese users using template emails from the Portuguese Government Finance & Tax and EDP. Figure 1: Lampion malware distributed via SAPO TRANSFER cloud. Lampion email templates – May 2020. com/team-modulosp/0.]zipzH$^Uj[jHf2ir0[%u%YiEj’elhKW@]s[`$5]0e6e:]`bB[<WLf7_Gi*$FYZe+cp%ojP[‘W;co#lcLeIZ]krb’eTimf(%PF=#Z’c(h#:/^$}Z~bZbjHhxx

Banking 106
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Brazilian trojan banker is targeting Portuguese users using browser overlay

Security Affairs

Since the end of April 2020, a new trojan has been affecting Portuguese users from several bank organizations. At least since the year of 2014 that new variants have been observed, with minor changes, and with the objective of collecting bank details of the victims. Technical Analysis.

Banking 110
article thumbnail

Ursnif: The Latest Evolution of the Most Popular Banking Malware

Security Affairs

ZLab Yoroi-Cybaze dissected another attack wave of Ursnif Trojan, aka Gozi ISFB, an offspring of the original Gozi which source code was leaked in 2014. ZLab Yoroi-Cybaze dissected another attack wave of Ursnif Trojan, aka Gozi ISFB, an offspring of the original Gozi which source code was leaked in 2014. Introduction.

Banking 84
article thumbnail

Latin American Javali trojan weaponizing Avira antivirus legitimate injector to implant malware

Security Affairs

Latin American Javali trojan weaponizing Avira antivirus legitimate injector to implant malware. In the last few years, many banking trojans developed by Latin American criminals have increased in volume and sophistication. Background of Latin American Trojans. the trojan loader/injector.

Antivirus 118
article thumbnail

New release of Lampion trojan spreads in Portugal with some improvements on the VBS downloader

Security Affairs

Expert spotted a new release of the Lampion trojan banker that was launched with fresh improvements in the way the malware loader operated. A new release of the Lampion trojan banker was launched with fresh improvements in the way the malware loader – the initial VBS file – is operating.

Malware 94