logo

Slave, Banatrix and ransomware

ID: 015771ed-30be-52c0-95e5-c5b447259c5b

STIX ID: report--015771ed-30be-52c0-95e5-c5b447259c5b

Feed Name: CERT Polska

Threat Score
70/100

Date Published: 2015-07-03

Date Updated: 2026-04-19

Author: Łukasz Siewierski

...
...

This report analyzes the 'Slave' Polish e-banking trojan (dropped by Andromeda), describing its email-based delivery, webinject-driven credential theft across Internet Explorer, Firefox and Chrome, stripping of CSP headers to evade bank reporting, Bitcoin-address clipboard hijacking, configuration retrieval behavior, provided sample hashes/VT scores, and likely ties to authors of earlier Polish malware such as Banatrix.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.