Retefe Revisited: Banking trojan reemerges, adopts new set of tools
#1
Quote:Researchers have noticed a recent upswing in attacks against banks featuring the Retefe banking trojan, following what was apparently a fairly quiet 2018 for the malware.
 
The trojan is historically known for targeting the banking industry in countries like Austria, Sweden, Switzerland and the UK. Rather than using malicious web injects to execute man-in-the-browser attacks — like many banking trojans do — it victimizes users by using a proxy to route online traffic intended for legitimate banking websites to malicious sites instead.

In April 2019, the malware began focusing its efforts on Swiss and German online banking customers using either Windows- or macOS-based machines, according to a blog post published today by the Proofpoint Threat Insight Team and company researcher Bryan Campbell.
 
This latest campaign changes some of the malware’s functionality as well. For instance, instead of using TOR for its proxy redirection and command-and-control set-up, Retefe uses Stunnel, an open-source application that acts as a proxy and universal TLS/SSL tunneling service.

“It is not clear why Retefe’s authors have now deprecated Tor in favor of stunnel. However, we suspect that the use of a dedicated tunnel rather than Tor makes for a more secure connection because it eliminates the possibility of snooping on the hops between Tor nodes,” Proofpoint surmises in the blog post. “Tor is also a ‘noisier’ protocol and thus would be easier to detect in an enterprise environment than Stunnel, which would appear as any other outbound SSL connection.”

SOURCE: https://www.scmagazine.com/home/security...__trashed/
[-] The following 2 users say Thank You to silversurfer for this post:
  • harlan4096, ismail
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
AMD releases ROCm 6.4, official RDNA4 su...
AMD ROCm 6.4 relea...harlan4096 — 10:05
Best Linux distros for reviving an old P...
Installing the rig...harlan4096 — 10:04
AhnLab, Inc.
AhnLab, Inc. Compute...jasonX — 09:58
QOwnNotes 19.1.6
25.4.0 All TODO...Kool — 16:06
YouTube updates Shorts view count metho...
This is a smart and ...Kiran78 — 11:41

[-]
Birthdays
Today's Birthdays
avatar (45)Rodneykak
avatar (48)tradeSmode
Upcoming Birthdays
avatar (44)wapedDow
avatar (48)oapedDow
avatar (41)Sanchowogy
avatar (45)MeighGoask
avatar (43)techlignub
avatar (42)Stevenmam
avatar (49)onlinbah
avatar (49)fuspeukChark
avatar (43)werriewWaiNg
avatar (37)Freemanleo
avatar (42)cdoubapKit
avatar (37)lystraPonia
avatar (30)smith8395john
avatar (50)steakelask
avatar (44)Termoplenka
avatar (42)bycoPaist
avatar (48)pieloKat
avatar (42)ilyagNeexy
avatar (50)donitascene
avatar (50)Toligo
avatar (37)RobertUtelt

[-]
Online Staff
There are no staff members currently online.

>