A banking malware called ZLoader that had last appeared in early 2018 has been detected in more than 100 email campaigns since the beginning of the year.
The Trojan is in active development with 25 versions appearing since its return in December 2019, with the latest being spotted this month.

The malicious spam campaigns target users in the US, Canada, Germany, Poland, and Australia with lures related to COVID-19 and invoices.
Researchers at Proofpoint note today in a report that the ZLoader distributed in this manner is different from the original variant observed between 2016 and 2018.
Multiple actors are distributing the virus strain in at least one malicious email campaign per day. They use PDF files that link to a Microsoft Word with macro code that downloads and executes a version of ZLoader.
Since March, COVID-19-themed phishing emails have been circulating. One of the emails pretends to warn recipients about scams related to the novel coronavirus pandemic.

IBM X-Force reported these campaigns as quite convincing with documents allegedly containing details about government relief payments.
The current variant lacks some of the advanced features seen in its predecessor. For example, it lacks code and string encryption. Nevertheless, it still poses a significant threat.
It uses web injects to steal credentials and private banking information from victims, as well as sensitive data stored in browsers, such as cookies and passwords.
The threat actor uses this data to log into the victim's online banking account. Using a VNC (Virtual Network Computing) client, they perform transactions from the compromised computer.
This does not raise suspicions with the bank, as the transfer is initiated from the customer's computer using correct credentials. It also makes it more difficult to dispute the fraudulent transaction
ZLoader is also known as Zeus Sphinx, Terdot, and DELoader. It is a variant of the infamous Zeus that was used to steal tens of millions in 2010.
In the past, Zeus was priced between $3000 and $4000 and was the top malware used by criminals specializing in financial fraud.
