RM3 – Curiosities of the wildest banking malware
ID: bb1af9f6-f5e5-5d4b-948f-bbbce283b669
STIX ID: report--bb1af9f6-f5e5-5d4b-948f-bbbce283b669
Feed Name: Fox-IT blog
This report analyzes the Gozi ISFB RM3 banking malware variant over ~30 months, detailing its PX file format, modular architecture (bl.dll, explorer.dll, rt.dll, netwrk.dll, browser hooks, keylog, VNC, socks, cmdshell), distribution channels (malspam, Spelevo), geographic targeting (primarily Australia/New Zealand, UK, Germany, Italy), and operational changes including AES migration and potential pivot toward ransomware-style lateral movement; it also provides IoCs (module hashes, campaign IDs), config samples, and TTPs for detection and tracking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
