X-Force April 13, 2020 Grandoreiro malware now targeting banks in Spain 6 min read - A familiar malware threat called Grandoreiro, a remote-overlay banking Trojan that typically affects bank customers in Brazil, has spread to attack banks in Spain.
X-Force April 1, 2020 Breaking the ice: A deep dive into the IcedID banking trojan’s new major version release 14 min read - Since 2017, the IcedID Trojan has received consistent updates that enable it to continue targeting banks and other businesses. Find out what changes were included in the latest major release.
March 30, 2020 Weekly Security News Roundup: 24 Children’s Gaming Apps Laden With Tekya Clicker 2 min read - Researchers found a new clicker malware called "Tekya" hidden within 24 children's games on the Google Play store. Read on to learn what else happened last week in security news.
Malware March 30, 2020 Zeus Sphinx Trojan Awakens Amidst Coronavirus Spam Frenzy 7 min read - The renewed Zeus Sphinx activity that IBM X-Force is seeing features a modified variant targeting online banking users in North America and Australia through the use of maldocs themed around COVID-19.
Advanced Threats March 24, 2020 TrickBot Pushing a 2FA Bypass App to Bank Customers in Germany 13 min read - Our team is closely monitoring TrickBot's developing capabilities, including its new cross-channel attacks using the TrickMo component.
February 11, 2020 KBOT Malware Is the First ‘Living’ Virus Spotted in Years 2 min read - Security researchers recently spotted KBOT malware, the first "living" computer virus they've discovered in years.
Banking & Finance February 3, 2020 CamuBot Resurfaces With Cross-Channel, Targeted Attacks in Brazil 6 min read - Recent CamuBot activity resurfaced exactly one year after IBM X-Force researchers made the initial discovery of this malware in September 2018.
Threat Hunting January 21, 2020 New NetWire RAT Campaigns Use IMG Attachments to Deliver Malware Targeting Enterprise Users 3 min read - IBM X-Force researchers have discovered a new campaign targeting organizations with fake business emails that deliver NetWire remote-access Trojan (RAT) variants.
Banking & Finance December 3, 2019 TrickBot Widens Infection Campaigns in Japan Ahead of Holiday Season 4 min read - The threat group operating the TrickBot Trojan has been modifying some of the malware's modules as they continue to deploy their attacks in the wild — most recently in Japan.
October 8, 2019 Geost Banking Botnet Has Infected 800,000 Android Users Since 2016 2 min read - A banking botnet called Geost used simple text messages and pop-ups to gain access to account information and other data belonging to more than 800,000 Android users since 2016.