<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Banking Trojan &#8211; First Hackers News</title>
	<atom:link href="https://firsthackersnews.com/category/malware/banking-trojan/feed/" rel="self" type="application/rss+xml" />
	<link>https://firsthackersnews.com</link>
	<description>Latest cybersecurity news, real attacks, and practical IOCs—made simple and actionable.</description>
	<lastBuildDate>Fri, 22 Sep 2023 04:00:36 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.5</generator>

<image>
	<url>https://firsthackersnews.com/wp-content/uploads/2026/03/cropped-FHN_512x512-32x32.png</url>
	<title>Banking Trojan &#8211; First Hackers News</title>
	<link>https://firsthackersnews.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>The new Android banking trojan is based on ERMAC</title>
		<link>https://firsthackersnews.com/hook-new-android-banking-trojan/</link>
					<comments>https://firsthackersnews.com/hook-new-android-banking-trojan/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 20 Sep 2023 02:14:36 +0000</pubDate>
				<category><![CDATA[Tips]]></category>
		<category><![CDATA[Banking Trojan]]></category>
		<category><![CDATA[BOTNET]]></category>
		<category><![CDATA[Compromised]]></category>
		<category><![CDATA[Evilproxy]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[android]]></category>
		<category><![CDATA[android banking]]></category>
		<category><![CDATA[banking trojan]]></category>
		<category><![CDATA[ERMAC]]></category>
		<category><![CDATA[HOOK]]></category>
		<category><![CDATA[malicious sms]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[security advisory]]></category>
		<category><![CDATA[security fix]]></category>
		<category><![CDATA[security update]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=6946</guid>

					<description><![CDATA[<p>A recent analysis of the Android banking trojan Hook has uncovered its foundation in its predecessor, ERMAC. Hook</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/hook-new-android-banking-trojan/">The new Android banking trojan is based on ERMAC</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>A recent analysis of the Android banking trojan Hook has uncovered its foundation in its predecessor, ERMAC.</p>



<h2 class="wp-block-heading"><strong>Hook : New Android banking trojan</strong></h2>



<p>In January 2023, ThreatFabric initially identified Hook, categorizing it as a &#8220;variant of ERMAC&#8221; available for purchase at a monthly rate of $7,000. These variants stem from the efforts of a malware author known as DukeEugene.</p>



<p>Hook extends the functionality of ERMAC with more features, supporting up to 38 additional commands compared to the latter.</p>



<p>ERMAC&#8217;s primary functionalities were crafted to include sending SMS messages, overlaying a phishing window atop legitimate applications, listing installed apps, gathering SMS messages, and retrieving recovery phrases for numerous cryptocurrency wallets.</p>



<p>Conversely, Hook takes an advanced approach, going beyond by live-streaming the victim&#8217;s screen and actively engaging with the user interface to secure complete control over the compromised device. It even captures images using the front camera, acquires cookies associated with Google login sessions, and pilfers recovery codes from additional cryptocurrency wallets.</p>



<p>Additionally, it has the capability to send SMS messages to multiple phone numbers, effectively propagating the malware to other users.</p>



<p>Despite these distinctions, both Hook and ERMAC are proficient in capturing keystrokes and exploiting Android accessibility services for overlay attacks, which enable them to overlay content on other applications and pilfer credentials from more than 700 apps. The roster of target applications is continuously acquired through dynamic requests to a remote server.</p>



<p>Malicious software families are also engineered to monitor clipboard events and substitute the copied content with an attacker-controlled wallet if the victim copies a genuine wallet address.</p>



<p>Most of the control and command (C2) servers for Hook and ERMAC are situated in Russia, with additional servers found in the Netherlands, the United Kingdom, the United States, Germany, France, Korea, and Japan.</p>



<p>As of April 19, 2023, the Hook project appears to have ceased, with DukeEugene announcing his departure for a &#8220;special military operation.&#8221; Another individual under the alias RedDragon will handle software support until customers&#8217; subscriptions expire.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow"><p>&#x200d;Follow Us on:<strong>&nbsp;<a rel="noreferrer noopener" href="https://twitter.com/Info_FHNews" target="_blank">Twitter</a>,<a rel="noreferrer noopener" href="https://www.instagram.com/first_hackers_news/" target="_blank">&nbsp;Instagram</a>,&nbsp;<a rel="noreferrer noopener" href="https://www.linkedin.com/in/firsthackers-news/" target="_blank">Facebook</a></strong>&nbsp;to get the latest security news!</p></blockquote>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/hook-new-android-banking-trojan/">The new Android banking trojan is based on ERMAC</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/hook-new-android-banking-trojan/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>MOVEit Transfer customers are being warned to fix a new, critical flaw</title>
		<link>https://firsthackersnews.com/moveit-transfer-critical-flaw/</link>
					<comments>https://firsthackersnews.com/moveit-transfer-critical-flaw/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Mon, 10 Jul 2023 14:55:08 +0000</pubDate>
				<category><![CDATA[Exploitation]]></category>
		<category><![CDATA[Backdoor]]></category>
		<category><![CDATA[Banking Trojan]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[Evilproxy]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[IOC's]]></category>
		<category><![CDATA[Linux Malware]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Malicious extension]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[Software Issues]]></category>
		<category><![CDATA[Attack]]></category>
		<category><![CDATA[critical flaw]]></category>
		<category><![CDATA[critical patch update]]></category>
		<category><![CDATA[CVE-2-23-36934]]></category>
		<category><![CDATA[MOVEit]]></category>
		<category><![CDATA[MOVEit transfer]]></category>
		<category><![CDATA[security advisory]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[security vulnerability]]></category>
		<category><![CDATA[sql injection]]></category>
		<category><![CDATA[SQL injection vulnerbaility]]></category>
		<category><![CDATA[sql queries]]></category>
		<category><![CDATA[targeted attack]]></category>
		<category><![CDATA[unauthorized]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=6688</guid>

					<description><![CDATA[<p>Progress is notifying customers about a newly discovered critical SQL injection vulnerability, identified as CVE-2023-36934, in its MOVEit</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/moveit-transfer-critical-flaw/">MOVEit Transfer customers are being warned to fix a new, critical flaw</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Progress is notifying customers about a newly discovered critical SQL injection vulnerability, identified as CVE-2023-36934, in its MOVEit Transfer software.</p>



<h2 class="wp-block-heading"><strong>MOVEit Transfer</strong></h2>



<p>The software at the center of the recent massive Clop ransomware breach, MOVEit Transfer, has been updated to address a critical SQL injection bug along with two additional vulnerabilities of lesser severity.</p>



<p>The SQL injection vulnerabilities enable attackers to manipulate queries in order to gain unauthorized access to a database or manipulate its contents by executing malicious code. These attacks exploit the absence of adequate input/output data sanitization in the targeted application.</p>



<p><br>The two SQL injection security issues impact various versions of MOVEit Transfer, including:</p>



<ul class="wp-block-list"><li>Versions 12.1.10 and earlier</li><li>Versions 13.0.8 and earlier</li><li>Versions 13.1.6 and earlier</li><li>Versions 14.0.6 and earlier</li><li>Versions 14.1.7 and earlier</li><li>Versions 15.0.3 and older.</li></ul>



<p>The second SQL injection flaw, identified as CVE-2023-36932, received a high severity rating because an attacker could exploit it after authentication.</p>



<p>A third vulnerability addressed by this patch is CVE-2023-36933, a high severity issue that allows attackers to cause an unexpected program termination.</p>



<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="1021" height="625" src="https://firsthackersnews.com/wp-content/uploads/2023/07/image-2.png" alt="" class="wp-image-6689" srcset="https://firsthackersnews.com/wp-content/uploads/2023/07/image-2-200x122.png 200w, https://firsthackersnews.com/wp-content/uploads/2023/07/image-2-300x184.png 300w, https://firsthackersnews.com/wp-content/uploads/2023/07/image-2-400x245.png 400w, https://firsthackersnews.com/wp-content/uploads/2023/07/image-2-600x367.png 600w, https://firsthackersnews.com/wp-content/uploads/2023/07/image-2-768x470.png 768w, https://firsthackersnews.com/wp-content/uploads/2023/07/image-2-800x490.png 800w, https://firsthackersnews.com/wp-content/uploads/2023/07/image-2.png 1021w" sizes="(max-width: 1021px) 100vw, 1021px" /></figure>



<p>In response to the significant impact of the security incident, the American software company has made the decision to implement a proactive measure by introducing monthly security updates known as &#8220;Service Packs.&#8221; </p>



<p>This new approach enhances the software upgrade process, enabling MOVEit Transfer administrators to apply fixes more efficiently and promptly than previous methods.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow"><p>&#x200d;Follow Us on:<strong> <a rel="noreferrer noopener" href="https://twitter.com/Info_FHNews" target="_blank">Twitter</a>,<a rel="noreferrer noopener" href="https://www.instagram.com/first_hackers_news/" target="_blank"> Instagram</a>, <a rel="noreferrer noopener" href="https://www.linkedin.com/in/firsthackers-news/" target="_blank">Facebook</a></strong> to get the latest security news!</p></blockquote>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/moveit-transfer-critical-flaw/">MOVEit Transfer customers are being warned to fix a new, critical flaw</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/moveit-transfer-critical-flaw/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>New QBot Banking Trojan Campaign Hijacks Business Emails to Spread Malware</title>
		<link>https://firsthackersnews.com/new-qbot-banking-trojan/</link>
					<comments>https://firsthackersnews.com/new-qbot-banking-trojan/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Tue, 18 Apr 2023 03:55:48 +0000</pubDate>
				<category><![CDATA[Tips]]></category>
		<category><![CDATA[Banking Trojan]]></category>
		<category><![CDATA[BOTNET]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Malicious extension]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[banking trojan]]></category>
		<category><![CDATA[business email]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[malicious campaigns]]></category>
		<category><![CDATA[malicious emails]]></category>
		<category><![CDATA[malicious payloads]]></category>
		<category><![CDATA[malware campaign]]></category>
		<category><![CDATA[phishing campaign]]></category>
		<category><![CDATA[qbot]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[security advisory]]></category>
		<category><![CDATA[security fix]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[suspicious activity]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=6289</guid>

					<description><![CDATA[<p>Researchers are seeing a “significant increase” in attacks deploying the Qakbot malware, which have targeted victims in Germany,</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/new-qbot-banking-trojan/">New QBot Banking Trojan Campaign Hijacks Business Emails to Spread Malware</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Researchers are seeing a “significant increase” in attacks deploying the Qakbot <a href="https://firsthackersnews.com/balada-injector-malware/">malware</a>, which have targeted victims in Germany, Argentina, Italy, Algeria, Spain, the U.S. and other countries with <a href="https://firsthackersnews.com/adobe-acrobat/">emails</a> containing <a href="https://firsthackersnews.com/adobe-acrobat/">PDF attachments</a> that deliver the banking trojan.</p>



<h2 class="wp-block-heading"><strong>What is QBOT ?</strong></h2>



<p>Qakbot, which was first detected in 2007, has since grown into a multi-purpose <a href="https://firsthackersnews.com/balada-injector-malware/">malware</a> with multiple functionalities, including tools for performing reconnaissance, exfiltrating data and delivering other payloads. Its modular nature gives it flexibility for keeping up with the evolving threat landscape, and the malware has recently seen growing popularity among a variety of threat groups that either use its various capabilities or any of its second-stage payloads.</p>



<figure class="wp-block-image"><img decoding="async" src="https://thehackernews.com/new-images/img/b/R29vZ2xl/AVvXsEi3175izlCZQM1f5OUj7sXx1HCEBiOlVI81lliGiTkLS247IzIyllKveJe0plUJvDs0DWS4em1fGnEvvGdoSlNrCGJnh5HqCnRjgmzhwm-Whf3cR1o2iEyGBL6cj24FaCwCkXEF59LiOZF0eMV2XIFO5xsL6_Ki9xU3as0fZLIFgzsYXw30UI8Dk97X/s728-e365/malware.png" alt="New QBot Banking Trojan Campaign Hijacks Business Emails to Spread Malware"/><figcaption><strong>Reference</strong> :Securelist</figcaption></figure>



<p>Attackers deploying the malware have previously relied on hijacked email threads (harvested in bulk from Microsoft ProxyLogon).Researchers said at least 4,500 spam emails have been sent in this wave of attacks, which they first observed April 4.</p>



<p>“The malware would be delivered through e-mail letters written in different languages — variations of them were coming in English, German, Italian, and French,” said Victoria Vlasova, Andrey Kovtun and Darya Ivanova, researchers with Kaspersky in a monday report.</p>



<p>“After the WSF file is deobfuscated, its true payload gets revealed: a PowerShell script encoded into a Base64 line,” Kaspersky wrote. “As soon as the user opens the WSF file from the archive, the PowerShell script will be discreetly run on the computer and use wget to download a DLL file from a remote server.”</p>



<p>&nbsp;Kaspersky has also observed some Qbot versions turning victims’ computers into proxy servers to facilitate traffic redirection.</p>



<h2 class="wp-block-heading"><strong>Qbot indicators of compromise</strong></h2>



<p><br><strong>MD5</strong><br>PDF files<br>253E43124F66F4FAF23F9671BBBA3D98<br>39FD8E69EB4CA6DA43B3BE015C2D8B7D</p>



<p><strong>ZIP archives<br></strong>299FC65A2EECF5B9EF06F167575CC9E2<br>A6120562EB673552A61F7EEB577C05F8</p>



<p><strong>WSF files<br></strong>1FBFE5C1CD26C536FC87C46B46DB754D<br>FD57B3C5D73A4ECD03DF67BA2E48F661</p>



<p><strong>DLL</strong><br>28C25753F1ECD5C47D316394C7FCEDE2</p>



<p><strong>Malicious links<br></strong>ZIP archive<br>cica.com[.]co/stai/stai.php<br>abhishekmeena[.]in/ducs/ducs.php</p>



<p><strong>DLL</strong><br>rosewoodlaminates[.]com/hea/yWY9SJ4VOH<br>agtendelperu[.]com/FPu0Fa/EpN5Xvh<br>capitalperurrhh[.]com/vQ1iQg/u6oL8xlJ<br>centerkick[.]com/IC5EQ8/2v6u6vKQwk8<br>chimpcity[.]com/h7e/p5FuepRZjx<br>graficalevi.com[.]br/0p6P/R94icuyQ<br>kmphi[.]com/FWovmB/8oZ0BOV5HqEX<br>propertynear.co[.]uk/QyYWyp/XRgRWEdFv<br>theshirtsummit[.]com/MwBGSm/lGP5mGh</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow"><p>Follow Us on:<strong>&nbsp;<a rel="noreferrer noopener" href="https://twitter.com/Info_FHNews" target="_blank">Twitter</a>,<a rel="noreferrer noopener" href="https://www.instagram.com/first_hackers_news/" target="_blank">&nbsp;Instagram</a>,&nbsp;<a rel="noreferrer noopener" href="https://www.linkedin.com/in/firsthackers-news/" target="_blank">Facebook</a></strong>&nbsp;to get the latest security news!</p></blockquote>



<p></p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/new-qbot-banking-trojan/">New QBot Banking Trojan Campaign Hijacks Business Emails to Spread Malware</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/new-qbot-banking-trojan/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
