ZeroHour
Malware

KRBanker

0 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

KRBanker Targets South Korea Through Adware and Exploit Kits

Unit 42 details KRBanker banking trojan targeting South Korean bank users via KaiXin exploit kit and NEWSPOT adware, using pharming and process hollowing.

KRBanker (aka Blackmoon) is a banking trojan targeting online banking users in the Republic of Korea, with roughly 2,000 unique samples and 200+ pharming servers observed by Unit 42 over six months. It is distributed through the KaiXin exploit kit exploiting Adobe Flash CVE-2014-0569 and CVE-2015-3133, and through the NEWSPOT adware update channel that also delivers the Venik trojan. The trojan uses process hollowing, retrieves pharming server IPs from Qzone profile nickname fields, and abuses Proxy Auto-Config with a local proxy to redirect banking traffic to forged sites.

Palo Alto Unit 42 · 29d agoMalware in the wildCVE-2014-0569CVE-2015-3133

Related CVEs

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.