logo

Secureserver.net Domain Abused in Widespread Banking Trojan Attacks

ID: 65761eed-9c4c-5b23-b959-88688359bac2

STIX ID: report--65761eed-9c4c-5b23-b959-88688359bac2

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2024-08-06

Date Updated: 2026-04-22

Author: do son

...
...

A multi-stage banking trojan campaign is using secureserver.net-hosted IP-based URLs to deliver obfuscated HTA/JS/VBS payloads that download an AutoIt binary which performs sophisticated checks (AV/VM/region/language), injects into the legitimate mobsync.exe process, connects to C2 servers, and exfiltrates system details and credentials targeting Spanish- and Portuguese-speaking regions including Latin America and Europe; indicators and mitigation advice are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.