Bolik Banking Trojan
First observed on July 2019, Bolik is an advanced polymorphic banking trojan currently targeting English-speaking countries.
Summary
First observed on July 2019, Bolik is an advanced polymorphic banking trojan currently targeting English-speaking countries.
Affected platforms
The following platforms are known to be affected:
Threat details
Bolik is typically delivered packaged within legitimate applications hosted on third-party sites, or via disguised download links on compromised legitimate sites. However, newer campaigns will use full copies of legitimate sites in an attempt to trick users into downloading the malware directly. Bolik's operator will take great care in producing these spoof sites, including using search engine optimisation and valid SSL certificates, in order to increase the likelihood of users visiting the sites.
Once installed, Bolik will attempt to extract user credentials from a number of applications, as well as attempting to phish sensitive information when users visit specific sites. Certain Bolik campaigns will also deliver the AZORult and Predator trojans.
Remediation steps
Type | Step |
---|---|
To prevent and detect a trojan infection, ensure that:
|
Last edited: 11 January 2022 1:22 pm