Remove 05
article thumbnail

Brazilian trojan banker is targeting Portuguese users using browser overlay

Security Affairs

One of the last occurrences was last December 2019, where the Lampion trojan operated in a very similar way, changing only the way the malware was distributed (via AWS S3 buckets and with the first stage encoded in a highly obfuscated VBS file). Malicious endpoints are still active at the moment of writing this report (05-05-2020).

article thumbnail

Grandoreiro Malware implements new features in Q2 2020

Security Affairs

One of the last analyzed samples (2020-05-21 – 8491a619dc6e182437bd4482d6e97e3a ) is scrutinized below. The sample was available for download between 2020-05-18 and 2020-05-22. According to ESET , “ Grandoreiro has been active at least since 2017 targeting Brazil and Peru, expanding to Mexico and Spain in 2019. “.