A New Wave Of WIN32/CAPHAW Attacks
ID: 8f14f9fc-035f-5344-a4ee-b670835b93d8
STIX ID: report--8f14f9fc-035f-5344-a4ee-b670835b93d8
Feed Name: Zscaler Security Research Blog
ThreatLabZ analyzes an active Win32/Caphaw banking trojan campaign that targets credentials for 24 financial institutions; the malware employs a domain generation algorithm (DGA), self-signed SSL-encrypted C2, process injection into explorer/iexplore, persistence via autorun/registry changes, anti-VM checks, and likely its initial delivery via a Java-focused exploit kit. The report provides example DGA domains, observed drop locations and filenames, API calls, registry modifications, and counts of samples and IPs to support detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
