Guildma Malware Expands Targets Beyond Brazil
#1
Bug 
Quote:Researchers at Avast have published a detailed analysis of a banking trojan they call Guildma.

Guildma originates in Brazil. In an analysis of the Brazilian hacking scene, Recorded Future noted that cultural (language isolation) and stringent banking rules have largely kept Brazilian banking malware within Brazil; but warned that this would probably not last forever. Guildma seems to be a case in point.

Avast has detected around 155,000 infection attempts this year alone. Ninety-eight percent are still in Brazil, but the malware is now also targeting 130 banks and web services such as Netflix, Facebook, Amazon, and Google Mail, around the world -- although still avoiding computers running in English.

Detections began to spike in May 2019, peaking in June 2019, but ongoing. It was in May that the hackers expanded their pool of bank targets, and also began targeting around 75 other web services around the world.

Guildma is distributed through targeted phishing, with victims addressed by name. The emails include a ZIP archive attachment containing a malicious LNK file. If this is opened, it uses WMI to silently download an XSL file, which in turn downloads all Guildma's modules via BITSAdmin, and executes a first stage loader that loads the modules.

SOURCE: https://www.securityweek.com/guildma-mal...ond-brazil
[-] The following 4 users say Thank You to silversurfer for this post:
  • harlan4096, ismail, jasonX, Mohammad.Poorya
Reply
#2
Very nice read there thanks!
[-] The following 3 users say Thank You to jasonX for this post:
  • harlan4096, ismail, silversurfer
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
QOwnNotes
26.6.5 Added edit...Kool — 12:03
Microsoft Edge Moves to Two-Week Release...
Microsoft has anno...harlan4096 — 10:44
Bitdefender 27.0.60.337
Bitdefender 27.0.6...harlan4096 — 07:57
K-Lite Codec Pack 19.7.5 / 19.7.6 Update
Changes in 19.7.6 ...harlan4096 — 07:56
HWMonitor 1.64 for Windows
HWMonitor 1.64 for...harlan4096 — 07:55

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (39)Tedscolo
avatar (46)brakasig
avatar (45)JamesReshy
avatar (47)Francisemefe
avatar (40)leoniDup
avatar (39)Patrizaancem
avatar (39)biobdam
avatar (40)storoBox
avatar (48)kinotHeemn
avatar (39)Ceballos1976
avatar (40)efynu

[-]
Online Staff
There are no staff members currently online.

>