HomeSecurityTedrade banking trojans target banking customers worldwide!

Tedrade banking trojans target banking customers worldwide!

Kaspersky researchers have analyzed four different families of Brazilian banking trojans, codenamed Tedrade, that have targeted banks in Europe, Brazil, and Latin America. The researchers believe that these four families of Tedrade banking trojans, codenamed Guildma, Javali, Melcoz, and Grandoreiro, originate from a Brazilian banking group that is developing its capabilities, targeting banking customers. Brazilian cybercrime is mainly focused on the development and commercialization of banking trojans.


The first of the Tedrade banking trojans, called Guildma, has been on the threat landscape since at least 2015, having initially been observed in attacks targeting exclusively Brazilian banking customers. The malicious code is constantly updated, having been enhanced with new features, while the team behind this malware has been expanding its list of targets over the years. In addition, the malware have shown a great deal of familiarity with legitimate tools, which they use to make the threat undetectable.


Kaspersky researchers noted that Guildma is largely spread through email that contain a malicious file in compressed format. The file types range from Visual Basic Script to LNK. Most of the phishing emails take the form of requests supposedly from businesses, packages sent via courier, and these emails often have the COVID-19. The emails always seem to be sent by companies and organizations.

Tedrade banking trojans


The Javali malware has been active since November 2017, primarily targeting banking customers located in Brazil and Mexico. Both Guildma and Javali perform multi-stage attacks and are spread via phishing emails, using compressed file attachments (e.g. .VBS, .LNK) or an HTML file that executes Javascript to download a malicious file. Researchers also observed that the malware uses the BITSAdmin tool to download additional modules. Its operators use this tool to avoid detection, since this tool is whitelisted by the Windows. Furthermore, the malware leverages alternative data to hide the presence of the downloaded payloads, and also uses DLL Search Order Hijacking to launch malware binaries.


According to the researchers, the payloads are stored encrypted in the file system and decrypted in memory as they are executed. The final payload installed on the system will monitor user activities, such as websites opened and applications run, and will also check if they are on the list of targets. When a target is detected, the module is executed, giving the hackers control over banking transactions. Once the final payload is installed on the target system, it monitors specific banking websites. When the victim opens these websites, the hackers will gain control of any financial transactions made by that user.


As for Melcoz, it is an open-source RAT developed by a group operating in Brazil since at least 2018, and has now expanded its activity to other countries, including Chile and Mexico. Melcoz can steal browser passwords and information from the clipboard and Bitcoin wallets, replacing the original wallet information with that under the attacker’s control. The attack begins by sending phishing emails containing a link to a downloadable MSI installer. VBS scripts in installer package (.MSI) files download the malware to the system and then abuse the AutoIt interpreter and VMware NAT service to load the malicious DLL onto the target system.

banks

The code monitors browser activity, looking for online banking sessions. Once detected, the malware allows the attacker to display an overlay window in front of the victim’s browser to manipulate their session. In this way, the “fraudulent” transaction is carried out from the victim’s device, making it more difficult for anti-fraud solutions to detect. The malicious code could also steal information related to a banking transaction, including a one-time password.


The latest Tedrade malware family, codenamed Grandoreiro, has been active since 2016, participating in a campaign that spread to banks in Brazil, Mexico, Portugal, and Spain. The malware is hosted on Google Sites and spreads via compromised websites and Google Ads, while attackers distribute it via phishing emails, as they do with the other three Tedrade malware families. Researchers observed that it uses a domain (DGA) to hide the C2 address used during the attack.

banks

Brazilian fraudsters are increasingly expanding their network of partners to include banks in other countries, adopting MaaS (malware-as-a-service) and rapidly adding new techniques to their malware. Tedrade banking trojans are trying to lead the way by using DGA, encrypted payloads, DLL hijacking, multiple LoLBins, fileless infections and other tricks to evade detection and analysis by banks. These threats are expected to evolve, targeting banks in even more countries.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS