Blog | G5 Cyber Security

Vxers abused legitimate VMware binary to spread Banking Trojan Distribution

Cisco researchers discovered a malware campaign abusing a legitimate VMware binary to spread a banking Trojan. The campaign mainly targeted Brazil users, the attackers used malicious spam emails featuring messages written in Portuguese that attempt to convince the victim to open a malicious HTML attachment posing as a Boleto invoice. The Java code first sets up the working environment of the malware and then downloads additional files from a remote server. Once the binaries are downloaded by the Java code, it renames them and executes a legitimate binary from VMware (signed with a. digital signature) in an attempt to trick security programs into trusting the libraries it would load.”]

Source: https://securityaffairs.co/wordpress/63629/cyber-crime/banking-trojan-vmware.html

Exit mobile version