logo

Spy Banker Trojan Telax Abusing Google Cloud Servers

ID: 2df2e5e1-35f6-5fbc-baef-23522d2c8f8e

STIX ID: report--2df2e5e1-35f6-5fbc-baef-23522d2c8f8e

Feed Name: Zscaler Security Research Blog

Threat Score
72/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ describes an active Spy Banker (Telax) campaign targeting Portuguese-speaking users in Brazil that uses social-engineering lures (coupon offers, fake apps) and shortened bit.ly links redirecting to Google Cloud-hosted payloads; the initial downloader retrieves a Delphi Telax payload which injects into vbc.exe, registers rootkit drivers, harvests banking credentials (including bypassing 2FA via fake panels), and communicates with C2 servers. The report provides filenames, domains, WHOIS data, distribution statistics, detailed module analysis, C2 commands, and numerous file hashes, and notes that Zscaler protections cover the observed samples.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.