A modified #multibank Brazilian #bankingtrojan is actively #phishing for Mexican banking credentials using an overlay that replicates active online banking pages. Arriving as a link on #tax invoice emails, #MicrosoftDefenderATP detects this trojan as Fuery or Fuerboos.
Interestingly, the trojan lets attackers interact with victims through the fake overlay connected to a C&C server possibly in the malware vector comprobantefiscalsatfolio[.]com.
The email link points to "folio-fiscal242211144 (1).zip", "factura folio-fiscal94077829.zip", or "SERICIOS MULTI GENERALES folio-fiscal660359864.zip", a ZIP that contains comprobantedigital39824a.exe or comprobantefiscal982sat.exe, which downloads the Trojan.
Known samples of this multi-bank trojan include: 327f8af69480b22291afe21a54cf1f695b0269c4c2f480b772e275f3b7bc37c0,
8f9b5aae1db1ed141a18bce969a37038f99c9a197f99dbe6f2f0f1cfb6fad9a0
More trojan samples: 275eb8b5f66348e383d835693f9fd2491c49a2cd7068c4f38742efc0ab34332a, 6706981d0a18f9617f9f261217cb0238fbd2083e8ef946d483271c6e49ec5bc8, 29ab4230c3ee1bf81bc67a0966fda875a8721ad2fb5fcec9add16bb17d2c8575
Share this Scrolly Tale with your friends.
A Scrolly Tale is a new way to read Twitter threads with a more visually immersive experience.
Discover more beautiful Scrolly Tales like this.
