NovaLoader—A Brazilian Banking Malware
ID: ff9ff82d-1fec-5889-b49f-2fff32a7d6cd
STIX ID: report--ff9ff82d-1fec-5889-b49f-2fff32a7d6cd
Feed Name: Zscaler Security Research Blog
NovaLoader is a multi-stage Brazilian banking malware campaign analyzed here; operators use encrypted VBS stages (first seen use of VBS for this family), encrypted downloads, VM detection, and a DLL loader executed via a copied rundll32 to load a Delphi final payload that performs overlay-style browser takeover and credential theft against Brazilian banks. The report details delivery methods (spam, social engineering, abuse of legitimate hosting services), C2 interactions (multiple contaw*.php endpoints and IPs), dropped filenames and MD5s, and provides IOCs (domains, IPs, and hashes) for detection and blocking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
