logo

New JavaScript Malware Targeted 50,000+ Users at Dozens of Banks Worldwide

ID: dd4e0a7d-72fd-5fa4-aec4-f025cda4f54e

STIX ID: report--dd4e0a7d-72fd-5fa4-aec4-f025cda4f54e

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2023-12-21

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

A March 2023 IBM Trusteer report details a sophisticated JavaScript web-injection campaign that altered banking login pages to capture credentials and one-time passwords across more than 40 financial institutions, affecting an estimated 50,000 user sessions worldwide. The obfuscated, dynamic scripts are served from a threat-controlled domain (jscdnpack.com), query a command-and-control server to determine actions (including inserting fake UI elements or showing downtime messages), and indicators suggest a possible connection to the DanaBot stealer/loader family; delivery vectors are suspected to include phishing and malvertising.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.