logo

Something nasty injected login-stealing JavaScript into 50K online banking sessions

ID: 7645d17a-ccc1-5a29-ae45-207bf42e7d22

STIX ID: report--7645d17a-ccc1-5a29-ae45-207bf42e7d22

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2023-12-20

Date Updated: 2026-04-26

Author: Jessica Lyons Hardcastle

...
...

IBM Security analysed a 2023 campaign attributed to DanaBot or a related Windows malware family that injects malicious JavaScript into bank login pages to capture credentials and MFA/OTP tokens; roughly 50,000 user sessions across 40+ banks worldwide were affected. The injected script communicates with a C2 server, supports multiple actions (e.g., OTP prompts, fake error pages, overlays), and removes itself from the DOM to hinder detection; the report includes indicators of compromise and mitigation advice. The article also briefly highlights AT&T Alien Labs' findings on JaskaGO, a separate Go-based info‑stealer.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.