Trend Micro discovered Lordfenix, a student who has created more than 100 different banking Trojans and other malicious tools since April 2013.
Security experts at Trend Micro have discovered a 20-year-old Brazilian student who has developed and distributed more than 100 banking malware.
The young cybercriminal, who used the aliases 'Lord fenix', 'Hacker's Son' and 'Filho de Hacker', had been selling each banking trojan for around US$300 since 2013.
Trend Micro said the student began his activity by approaching interested parties on hacking forums, where he found the cooperation of other malware authors.
Since its inception, Lordfenix has "developed his skills" and consequently grown his business by developing malware based on the needs of his clients.
Lord fenix began his activity by offering free versions of the fully-functional source code of the banking Trojan on the underground forum.
The free version was designed to target customers of four Brazilian banks, including Bank of Brazil, Caixa, and HSBC Brazil.
The model he followed was effective: Lordfenix offered further customization of banking trojans to target other financial institutions.
"Lordfenix has since continued to develop and sell banking Trojans, one of which we have detected as TSPY_BANKER.NJH. This Trojan is able to identify whenever a user types any of its target bank URLs. Among these targets are Banco de Brasil, Caixa, and HSBC Brasil," Trend Micro said in a statement.

Over the years, Lord Fenix has improved its malware by adding further features, such as protection against security products.
Lord fenix malware is able to detect and terminate the GbpSV.exe process associated with the G-Buster Browser Defense software, a security program used by many Brazilian banks to protect their users.
