Thread Rating:
  • 1 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Guildma Malware Expands Targets Beyond Brazil
#1
Bug 
Quote:Researchers at Avast have published a detailed analysis of a banking trojan they call Guildma.

Guildma originates in Brazil. In an analysis of the Brazilian hacking scene, Recorded Future noted that cultural (language isolation) and stringent banking rules have largely kept Brazilian banking malware within Brazil; but warned that this would probably not last forever. Guildma seems to be a case in point.

Avast has detected around 155,000 infection attempts this year alone. Ninety-eight percent are still in Brazil, but the malware is now also targeting 130 banks and web services such as Netflix, Facebook, Amazon, and Google Mail, around the world -- although still avoiding computers running in English.

Detections began to spike in May 2019, peaking in June 2019, but ongoing. It was in May that the hackers expanded their pool of bank targets, and also began targeting around 75 other web services around the world.

Guildma is distributed through targeted phishing, with victims addressed by name. The emails include a ZIP archive attachment containing a malicious LNK file. If this is opened, it uses WMI to silently download an XSL file, which in turn downloads all Guildma's modules via BITSAdmin, and executes a first stage loader that loads the modules.

SOURCE: https://www.securityweek.com/guildma-mal...ond-brazil
[-] The following 4 users say Thank You to silversurfer for this post:
  • harlan4096, ismail, jasonX, Mohammad.Poorya
Reply
#2
Very nice read there thanks!
[-] The following 3 users say Thank You to jasonX for this post:
  • harlan4096, ismail, silversurfer
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Malwarebytes 5.1.3.110
Malwarebytes 5.1.3...Mohammad.Poorya — 00:51
Music Videos
Billy Joel - The Riv...jAcos — 17:24
Movies! Movies!
Beverly Hills Cop: A...jAcos — 17:22
TV Series
Matlock Kathy Bat...jAcos — 17:16
F-Secure 19.4
What's new in the ...harlan4096 — 09:44

[-]
Birthdays
Today's Birthdays
avatar (42)techlignub
avatar (41)Stevenmam
avatar (48)onlinbah
Upcoming Birthdays
avatar (43)wapedDow
avatar (49)steakelask
avatar (43)Termoplenka
avatar (41)bycoPaist
avatar (47)pieloKat
avatar (41)ilyagNeexy
avatar (49)donitascene
avatar (49)Toligo

[-]
Online Staff
There are no staff members currently online.

>