Retefe Banking Trojan is back

Der.Reisende

Level 45
Thread author
Honorary Member
Top Poster
Content Creator
Malware Hunter
Dec 27, 2014
3,423
In short, this one does the same the previous version did, hijacking your browser to redirect you to a phishing site. Currently most hit are Switzerland, Japan, Austria and Sweden.
After the user runs the file (.js dropper attached to mails), it deletes itself to hide traces of infection.
It hijacks DNS / Certificate to make your browser believe you visit a trusted page (and to redirect you) and to stay undetected by AV.

For our German readers, here''s an interesting German article on this topic:
Banking-Trojaner Retefe ist zurück

Thank you for reading :)
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top