Banjori Banking Trojan
First observed in 2013, Banjori is a banking trojan targeting users throughout Western Europe and the USA.
Summary
First observed in 2013, Banjori is a banking trojan targeting users throughout Western Europe and the USA.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, it is unclear how Banjori is initially delivered, although there are unconfirmed reports indicating it may distributed in spam email campaigns.
Once installed, Banjori will inject hooks into all browser-related processes. It will then monitor these to determine if a user visits a banking site, at which point it will attempt to phish or otherwise obtain their data. A secondary module will check the system language and search for sensitive files in the Users folder. Any extracted information is then sent back to a command and control server.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect a trojan infection, ensure that:
|
Last edited: 14 February 2020 2:58 pm