New Banking Trojan CHAVECLOAK Targets Brazilian Users via Phishing Tactics

News Archive
0 Replies 1,324 Views

silversurfer

Super Moderator
Verified
Top Poster
Staff Member
Malware Hunter
Forum Veteran
Users in Brazil are the target of a new banking trojan known as CHAVECLOAK that's propagated via phishing emails bearing PDF attachments.

"This intricate attack involves the PDF downloading a ZIP file and subsequently utilizing DLL side-loading techniques to execute the final malware," Fortinet FortiGuard Labs researcher Cara Lin said.

The attack chain involves the use of contract-themed DocuSign lures to trick users into opening PDF files containing a button to read and sign the documents.

In reality, clicking the button leads to the retrieval of an installer file from a remote link that's shortened using the Goo.su URL shortening service.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top