Guildma Malware Expands Targets Beyond Brazil
#1
Bug 
Quote:Researchers at Avast have published a detailed analysis of a banking trojan they call Guildma.

Guildma originates in Brazil. In an analysis of the Brazilian hacking scene, Recorded Future noted that cultural (language isolation) and stringent banking rules have largely kept Brazilian banking malware within Brazil; but warned that this would probably not last forever. Guildma seems to be a case in point.

Avast has detected around 155,000 infection attempts this year alone. Ninety-eight percent are still in Brazil, but the malware is now also targeting 130 banks and web services such as Netflix, Facebook, Amazon, and Google Mail, around the world -- although still avoiding computers running in English.

Detections began to spike in May 2019, peaking in June 2019, but ongoing. It was in May that the hackers expanded their pool of bank targets, and also began targeting around 75 other web services around the world.

Guildma is distributed through targeted phishing, with victims addressed by name. The emails include a ZIP archive attachment containing a malicious LNK file. If this is opened, it uses WMI to silently download an XSL file, which in turn downloads all Guildma's modules via BITSAdmin, and executes a first stage loader that loads the modules.

SOURCE: https://www.securityweek.com/guildma-mal...ond-brazil
[-] The following 4 users say Thank You to silversurfer for this post:
  • harlan4096, ismail, jasonX, Mohammad.Poorya
Reply
#2
Very nice read there thanks!
[-] The following 3 users say Thank You to jasonX for this post:
  • harlan4096, ismail, silversurfer
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
XYplorer
What's new in Rele...Kool — 09:30
Sysinternals Suite 3.26.2026
What's New (March ...harlan4096 — 11:40
AxCrypt 3.0.0.83
AxCrypt 3.0.0.83: ...harlan4096 — 11:39
Microsoft Edge 146.0.3856.84
Version 146.0.3856...harlan4096 — 11:37
PowerToys 0.98.1
Release v0.98.1 ...harlan4096 — 11:37

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
No upcoming birthdays.

[-]
Online Staff
harlan4096's profile harlan4096
Administrator

>