logo

Banking Malware Uses PAC File

ID: 72ac7691-cc54-5832-a301-d02d9df29412

STIX ID: report--72ac7691-cc54-5832-a301-d02d9df29412

Feed Name: Zscaler Security Research Blog

Threat Score
60/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report documents a malware sample that modifies the Windows registry Internet Settings AutoConfigURL to point to an attacker-controlled PAC file (http://dns.configdeskwork.com:8099/workwindows.pac). The PAC causes targeted banking and other traffic (including Brazilian sites and American Express) to be proxied to 208.64.66.170, enabling credential theft; the report includes the PAC content, registry key used, FQDN and resolved IP as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.