IBM security researchers have spotted a new banking trojan named MnuBot that uses some atypical tricks to avoid easy detection on compromised hosts. The malware is controlled by crooks via a remote Microsoft SQL (MSSQL) database. The author is currently spreading it to Brazilian targets only. IBM Security’s Trusteer’s group says the malware’s source code contains encrypted credentials to connect to a remote MSSQL database. This is somewhat untypical, as most malware operates by pinging remote custom-crafted web servers or web apps.
Source: https://www.bleepingcomputer.com/news/security/mnubot-banking-trojan-tries-to-hide-behind-seemingly-innocent-mssql-traffic/

