October 16, 2015 By Shane Schick 2 min read

Researchers are warning that usernames, passwords and other credentials of online banking users in Japan may be compromised thanks to a Trojan that builds off of previous vulnerabilities in Adobe Flash Player and Microsoft’s Internet Explorer (IE).

An alert from ESET, which provides online scanning tools, offered details on Brolux, a Trojan that cybercriminals are using to track online banking activity by monitoring the URLs consumers visit. Brolux works by installing a pair of configuration files that contain both URLs that can be cross-referenced and popular Japanese financial services firms’ window titles. If cybercriminals see an opportunity, potential victims are directed to a page that resembles the country’s Financial Services Agency or the Japanese Public Prosecutor’s Office.

As SecurityWeek pointed out, this is just the latest instance of malware creators targeting Japanese online banking users. Although the degree of organized cybercrime in the country is believed to be in its early stages, according to a study from Trend Micro, similar threats hitting customers of financial institutions include malware such as Neverquest, Tsukuba and Shifu.

One of the interesting aspects of Brolux is its use of previously reported bugs in Flash Player and the so-called Unicorn vulnerability in IE. We Live Security compared the malware’s distribution method through an adult website to Win32/Aibatook, which also focused on Japanese online banking customers. In this case, however, the site luring potential victims is aggregating pornographic images and videos from other sites.

Hopefully, anyone who hasn’t already updated or patched Flash Player and IE will do so as news of Brolux spreads. In the meantime, expect many similar threats to emerge as cybercriminals simply modify or tweak previous vulnerabilities and exploits to distribute malware. Shifu, for example, made use of the widely known Angler exploit kit to go after online banking users in the U.K. Other features in Shifu were also reportedly copied from previous Trojans.

In other words, cybercriminals are making no attempt to be original here; they’re simply being as persistent as possible in the hopes of gaining control of more personal information over time.

More from

When ransomware kills: Attacks on healthcare facilities

4 min read - As ransomware attacks continue to escalate, their toll is often measured in data loss and financial strain. But what about the loss of human life? Nowhere is the ransomware threat more acute than in the healthcare sector, where patients’ lives are literally on the line.Since 2015, there has been a staggering increase in ransomware attacks on healthcare facilities. And the impacts are severe: Diverted emergency services, delayed critical treatments and even fatalities. Meanwhile, the pledge some ransomware groups made during…

AI and cloud vulnerabilities aren’t the only threats facing CISOs today

6 min read - With cloud infrastructure and, more recently, artificial intelligence (AI) systems becoming prime targets for attackers, security leaders are laser-focused on defending these high-profile areas. They’re right to do so, too, as cyber criminals turn to new and emerging technologies to launch and scale ever more sophisticated attacks.However, this heightened attention to emerging threats makes it easy to overlook traditional attack vectors, such as human-driven social engineering and vulnerabilities in physical security.As adversaries exploit an ever-wider range of potential entry points…

4 trends in software supply chain security

4 min read - Some of the biggest and most infamous cyberattacks of the past decade were caused by a security breakdown in the software supply chain. SolarWinds was probably the most well-known, but it was not alone. Incidents against companies like Equifax and tools like MOVEit also wreaked havoc for organizations and customers whose sensitive information was compromised.Expect to see more software supply chain attacks moving forward. According to ReversingLabs' The State of Software Supply Chain Security 2024 study, attacks against the software…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today