Posts

Showing posts with the label DanaBot

HookAds Malvertising Uses Fallout Exploit Kit to Distribute Malware

Image
Another HookAds Malvertising Campaign has been reported to be active recently, which is redirecting the potential visitors to the Fallout Exploit Kit. Following the activation, the kit will strive to capitalize on the known susceptibilities in Windows to download & install malicious malware in the infected system. The malign malware include DanaBot banking  Trojan , GlobeImposter  Ransomware  and the Nocturnal information & data stealer. Insight in HookAds Malvertising Campaign The HookAds Malvertising Campaign acquires contemptible ad space on cheap quality ad networks that are commonly used by online games sites, adult web sites or blackhat SEO Sites. These pernicious ads include JavaScript that redirects the innocent visitors through a string of tempting sites. One such enticing site was discovered last week by Exploit Kit Expert nao_sec. The sites resemble the pages filled with online games, local advertisements or other low quality pages. Unawar...

Danabot Banking Trojan Targets Banks in the United States

Image
Over the past few months, banking  Trojans  have disseminated their global impact by almost 50 %.  The appropriate security measures adopted by banks to strengthen their processes have proven futile with the never-before seen tactics evolved by the developers to facilitate the theft of online funds. Banking Trojans  continue to be a popular tool among cyber maniacs for stealing user’s banking details and draining bank accounts. The discovery of  Danabot, another Banking Trojan  in a row is an evidence to establish the fact. With the widely- reported initial campaigns in Australia, this banking Trojan later expanded its reach to European countries particularly Austria, Poland, Italy, Germany, Ukraine, its latest target being United States.   What is DanaBot? DanaBot is a modular Banking Trojan , first discovered in  malicious email campaigns  targeting Australian population in May 2018. This malware is programmed in  Delphi , an Int...