New JavaScript Malware Targeted 50,000+ Users at Dozens of Banks Worldwide
ID: dd4e0a7d-72fd-5fa4-aec4-f025cda4f54e
STIX ID: report--dd4e0a7d-72fd-5fa4-aec4-f025cda4f54e
Feed Name: The Hacker News
A March 2023 IBM Trusteer report details a sophisticated JavaScript web-injection campaign that altered banking login pages to capture credentials and one-time passwords across more than 40 financial institutions, affecting an estimated 50,000 user sessions worldwide. The obfuscated, dynamic scripts are served from a threat-controlled domain (jscdnpack.com), query a command-and-control server to determine actions (including inserting fake UI elements or showing downtime messages), and indicators suggest a possible connection to the DanaBot stealer/loader family; delivery vectors are suspected to include phishing and malvertising.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
