Banatrix successor – swapping acct numbers with a Firefox add-on
ID: 0fd79647-3eeb-5a86-8811-b97bf39c8a1d
STIX ID: report--0fd79647-3eeb-5a86-8811-b97bf39c8a1d
Feed Name: CERT Polska
**Executive Summary:** This report analyzes a Polish-targeted banking malware campaign (attributed to Banatrix authors) that infects users via trojanized installers, uses a dropper to place wget and create a scheduled task to fetch a payload, and installs a Firefox add-on which intercepts banking traffic to replace recipient account numbers with mule accounts and capture transaction screenshots; the document includes technical details, mitigation advice (update Firefox), and SHA256 hashes for identified samples.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
