ESET security researchers have identified a new version of banking malware, which is being spread through Japanese pornographic.
The malware, which belongs to the Win32/Aibatook malware family, has been used in previous campaigns. However, the advanced version of the malware is not written in Delphi, but in C++. It also appears that there have been changes to the way the malware is distributed and how it steals information from potential targets.
Researchers report that malicious actors do not rely on entire exploit kits to infect systems, but instead use only one exploit at a time.
The malware is spread through websites with inappropriate content and exploits a Java vulnerability with the identifier CVE 2013-2465.
At least four domains have been compromised so far and are being used to distribute the malware, including high-traffic websites – currently among the top 2,000 most popular websites in Japan.

