HomeSecurityNew banking trojan spreads via RTF files

New banking trojan spreads via RTF files

Brazilian-banking-trojan-embedded-in-rtf

Kaspersky security researchers have identified a new and interesting spam campaign targeting customers of banks and financial institutions in Brazil.

The campaign is based on sending emails to potential victims, which supposedly come from banks and contain a malicious attachment titled “Comprovante_Internet_Banking.rtf”.

Typically, attachments are executable files presented as PDF files. In this case, however, the attachment is simply an RTF file, which is seemingly harmless.

When the user opens the file, a thumbnail image is displayed accompanied by the following message: “Click to view larger.” Once users click on the image, a new message appears stating that a CPL file is about to be executed.

The file is a banking trojan written in Delphi, which Kaspersky detects as “Trojan.Win32.ChePro”.

But how did cybercriminals manage to insert malware into a text document?! RTF files, like some other word processing programs, allow the user to insert file objects into documents, even executable files.

Thus, attackers, taking advantage of this possibility, managed to embed malware into the seemingly "harmless" text file, with the aim of deceiving unsuspecting users.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS