logo

Banatrix successor – swapping acct numbers with a Firefox add-on

ID: 0fd79647-3eeb-5a86-8811-b97bf39c8a1d

STIX ID: report--0fd79647-3eeb-5a86-8811-b97bf39c8a1d

Feed Name: CERT Polska

Threat Score
70/100

Date Published: 2016-01-21

Date Updated: 2026-04-19

Author: Malgorzata Debska

...
...

**Executive Summary:** This report analyzes a Polish-targeted banking malware campaign (attributed to Banatrix authors) that infects users via trojanized installers, uses a dropper to place wget and create a scheduled task to fetch a payload, and installs a Firefox add-on which intercepts banking traffic to replace recipient account numbers with mule accounts and capture transaction screenshots; the document includes technical details, mitigation advice (update Firefox), and SHA256 hashes for identified samples.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.