Security experts from Fidelis firm spotted a new version of the Vawtrak banking Trojan that includes significant improvements such as the SSL pinning. The threat leverages on certificate pinning which isnt so common for malware. The new variant of the trojan uses a DGA mechanism to generates domains with a pseudorandom number generator (PRNG) discovered in the loader. It also uses a public key from the initial key to verify the signature hash that was passed in the SubjectKeyIdentifier field of the certificate.”]
Source: http://securityaffairs.co/wordpress/50368/malware/vawtrak-banking-trojan.html

