Vawtrack, also known as Snifula or NeverQuest, is one of today's most popular banking trojans, ranking fourth in 2015, according to Symantec. The trojan is available for rent on the Dark Web in the form of a Malware-as-a-Service offering. Many different criminal groups rent it out, each distributing it through their own methods.
In a report released last week, SophosLabs revealed that it had detected a new campaign using spam emails claiming to be shipping deliveries. These emails contained boobytrapped Word documents that asked the user to enable macros.
Enabling Word macros would trigger a series of automated scripts that would download and install the Pony infostealer malware. The crooks use this malware for local reconnaissance, and if they find valuable data that could be stolen, they would then deliver the Vawtrack v2 trojan.
Researchers point out that, compared to v1, v2 includes support for new targets. Vawtrack v1 is known to have targeted banks in Germany, Poland, Japan, the US, Saudi Arabia, the United Arab Emirates, Malaysia, Portugal, Spain, and the UK.
In v2, the authors of Vawtrack also added support for Canada, Israel, Romania, the Czech Republic and the Republic of Ireland. Additionally, Vawtrack implemented new targets for previously supported countries, such as the United Kingdom, the USA and Japan.
However, SohposLabs did not consider these new Vawtrack WebInject modules to be the most significant changes added to Vawtrack v2. The security firm says that the trojan now takes up much less disk space and features a modular architecture that allows criminals to send new modules to each infected target, expanding its capabilities.
Additionally, Vawtrack v2 has been hardened against reverse-engineering procedures, typically carried out by infosec researchers. SohposLabs says that v2 broke many security tools used for malware analysis.
The use of the difficult-to-understand levels and the changes in the trojan's encryption have considerably delayed the analysis of this trojan.
“The new version of Vawtrak shows that the botnet is alive and well, with active developers and a thriving customer base,” SophosLabs notes. “The rate at which new builds are being introduced suggests that product releases are occurring frequently.”
The company states, also, that the owners of Vawtrack continuously add new C&C servers to their infrastructure, which leads to the fact that it is a rapidly growing business.
Readers interested in SophosLabs' white paper on Vawtrack v2 can download it here.

