Blog | G5 Cyber Security

New Banking Trojan MnuBot uses SQL Server for Command and Control

IBM X-Force Research team discovered a new Delphi-based banking Trojan dubbed MnuBot that leverages Microsoft SQL Server for communication with the command and control (C&C) Experts found SQL server details (server address, port, username, and password) hardcoded inside the malware in an encrypted form. The malware downloads the malicious payload in as C:UsersPublicNeon.exe, this binary contains the attack logic. Mnubot uses the configuration to dynamically change the malicious activity (e.g., the banking sites that are targeted)”]

Source: https://securityaffairs.co/wordpress/73032/malware/mnubot-trojan-sql-server.html

Exit mobile version