Spy Banker Trojan Telax Abusing Google Cloud Servers
ID: 2df2e5e1-35f6-5fbc-baef-23522d2c8f8e
STIX ID: report--2df2e5e1-35f6-5fbc-baef-23522d2c8f8e
Feed Name: Zscaler Security Research Blog
Zscaler ThreatLabZ describes an active Spy Banker (Telax) campaign targeting Portuguese-speaking users in Brazil that uses social-engineering lures (coupon offers, fake apps) and shortened bit.ly links redirecting to Google Cloud-hosted payloads; the initial downloader retrieves a Delphi Telax payload which injects into vbc.exe, registers rootkit drivers, harvests banking credentials (including bypassing 2FA via fake panels), and communicates with C2 servers. The report provides filenames, domains, WHOIS data, distribution statistics, detailed module analysis, C2 commands, and numerous file hashes, and notes that Zscaler protections cover the observed samples.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
