Banking 

Advanced Espionage Tool  Adware  AI  Android  APP  APPX file  ATM Malware  Backdoor  Banking  Bookit  Bot  BotNet  Code-injection  CoinMiners  Crypt  Cryptocurrency  Cryptojacking  CyberSpy  Data Wiper  DDoS  DEAMON  Destructive Malware  DNS Backdoor  Downloader  Driver  Droper  EDR and AV Killer  ELF   ENGINE  Espionage  Exploit  Families  Fileless  FRAMEWORK  FUD Engine  Go  GPT  GPU  GRU Malware  HTML  ICS  InfoStealer  Injector  iOS  IoT  IRC  ISS   Java  JavaScipt  JSON  Keylogger  Killer  Kit  LINUX   Loader  Maas  MacOS  Macro  Malware  Military Malware  Miner  Mobil  MultiOS  nmp  OS  OSX   OT malware  P2P virus  Password STEALER  Pay-per-install (PPI)  PoS Malware  PowerShell  Program  PyPI   Python  QR trojan  Ransom  Raspberry  RAT  Roque  Rootkit  SMS  Spy  Spyware  SQL Malware  Stealer  SymbOS  Tool  Trojan  TV  UEFI bootkit  USB  Utility  VBA Macro  VBE  VBS  VHD malware  Virus  Vishing toolset  VMware ESXi  Windows  Wipper  WM virus  Worm  Wrapper 

20.08.26 Manic Manic: Blend between Banking Malware & Spyware MALWARE BANKING
08.07.26 UAT-7810 UAT-7810 continues building ORB networks using new malware MALWARE BANKING
16.06.26 Rokarolla  Rokarolla : Android Banker with Complete Device Takeover Capabilities MALWARE BANKING
06.06.26 OverlayPhantom Cyble analyzes OverlayPhantom, an Android banking trojan targeting 180+ apps across 10 countries, stealing credentials via fake overlays and real-time screen streaming. MALWARE BANKING
09.05.26 TCLBANKER TCLBANKER: Brazilian Banking Trojan Spreading via WhatsApp and Outlook MALWAREs BANKING

13.03.26

VENON

VENON: The First Brazilian Banker RAT in Rust

MALWARE

BANKING RAT

12.11.25

Maverick

Maverick: a new banking Trojan abusing WhatsApp in a mass-scale distribution

MALWARE

Banking Trojan

12.11.25

Coyote Banking Trojan

Coyote Banking Trojan Extends Reach & Targets Users through WhatsApp

MALWARE

Banking Trojan

13.10.25

Astaroth

Astaroth: Banking Trojan Abusing GitHub for Resilience

MALWARE

Banking

03.10.25

Klopatra

Klopatra: exposing a new Android banking trojan operation with roots in Turkey

MALWARE

Banking

26.08.25

Hook Version 3

Hook Version 3: The Banking Trojan with The Most Advanced Capabilities

MALWARE

Banking

23.06.25

GodFather 

GodFather Malware Returns Targeting Banking Users

MALWARE

BANKING

23.06.25

FjordPhantom

Promon discovers new Android banking malware, “FjordPhantom”

MALWARE

BANKING

05.02.25

Coyote Banking Trojan

Coyote Banking Trojan: A Stealthy Attack via LNK Files

MALWARE

Banking

10.12.24

Antidot 

AppLite: A New AntiDot Variant Targeting Mobile Employee Devices

MALWARE

BANKING

06.11.24

ToxicPanda

ToxicPanda: a new banking trojan from Asia hit Europe and LATAM

MALWARE

BANKING

28.10.24

Grandoreiro

Grandoreiro, the global trojan with grandiose goals

MALWARE

BANKING

27.10.24

TrickMo

Expanding the Investigation: Deep Dive into Latest TrickMo Samples

MALWARE

BANKING

14.09.24

TrickMo

A new TrickMo saga: from Banking Trojan to Victim's Data Leak

MALWARE

Banking

13.09.24

Ajina.Banker 

Ajina attacks Central Asia: Story of an Uzbek Android Pandemic

MALWARE

Banking

08.07.24

Mekotio

Mekotio Banking Trojan Threatens Financial Systems in Latin America

MALWARE

Banking

15.06.24

Grandoreiro

Smishing Triad Is Targeting Pakistan To Defraud Banking Customers At Scale

MALWARE

Banking

20.05.24

Grandoreiro 

Grandoreiro banking trojan unleashed: X-Force observing emerging global campaigns

MALWARE

Banking

03.04.24

Mispadu

Breaking Boundaries: Mispadu's Infiltration Beyond LATAM

MALWARE

Banking

14.03.24

Mispadu

According to ESET Research, Mispadu is an ambitious Latin American banking trojan that utilizes McDonald’s malvertising and extends its attack surface to web browsers.

MALWARE

Banking

12.03.24

CHAVECLOAK

FortiGuard Labs recently uncovered a threat actor employing a malicious PDF file to propagate the banking Trojan CHAVECLOAK. 

MALWARE

Banking

28.02.24

Mispadu

According to ESET Research, Mispadu is an ambitious Latin American banking trojan that utilizes McDonald’s malvertising and extends its attack surface to web browsers.

MALWARE

Banking

27.02.24

Ousaban

Ousaban: LATAM Banking Malware Abusing Cloud Services

MALWARE

Banking

27.02.24

Mekotio

Tweet on recent Mekotio Banker campaign

MALWARE

Banking

27.02.24

Astaroth

First spotted in the wild in 2017, Astaroth is a highly prevalent, information-stealing Latin American banking trojan. It is written in Delphi and has some innovative...

MALWARE

Banking

09.02.24

Coyote

Coyote: A multi-stage banking Trojan abusing the Squirrel installer

MALWARE

Banking

31.01.24

Grandoreiro

Grandoreiro is one of the many Latin American banking trojans such as Javali, Melcoz, Casabeniero, Mekotio, and Vadokrist, ....

MALWARE

Banking 

29.12.23

TinyNuke

TinyNuke (aka Nuclear Bot) is a fully-fledged banking trojan including HiddenDesktop/VNC server and a reverse socks4 server.

MALWARE

Banking

26.12.23

Carbanak

MyCERT states that Carbanak is a remote backdoor designed for espionage, data exfiltration, and to remote control. 

MALWARE

Banking

11.12.23

TrickMo’s

TrickMo’s Return: Banking Trojan Resurgence With New Features

MALWARE

Banking

21.11.23

QakBot

QBot is a modular information stealer also known as Qakbot or Pinkslipbot. It has been active for years since 2007.

MALWARE

Banking

23.09.23

BBtok

360 Security Center describes BBtok as a banking trojan targeting Mexico. 

MALWARE

Banking

23.09.23

BBtok

360 Security Center describes BBtok as a banking trojan targeting Mexico. 

MALWARE

Banking

06.09.23

Chaes

Chae$ 4: New Chaes Malware Variant Targeting Financial and Logistics Customers

MALWARE

Banking

01.08.23

WikiLoader

Organizations in Italy are the target of a new phishing campaign that leverages a new strain of malware called WikiLoader with an ultimate aim to install a banking trojan, stealer.

MALWARE

Banking

25.07.23

Casbaneiro 

According to BitDefender, Metamorfo is a family of banker Trojans that has been active since mid-2018.

MALWARE

Banking

10.07.23

TOITOIN 

Discover the intricate layers of a new sophisticated and persistent malware campaign targeting businesses in the LATAM region delivering the TOITOIN Trojan.

MALWARE

Banking

27.06.23

Anatsa 

Anatsa banking Trojan hits UK, US and DACH with new campaign

MALWARE

Banking

11.04.23

Xenomorph 

Xenomorph is a Android Banking RAT developed by the Hadoken.Security actor. 

MALWARE

Banking RAT

23.03.23

Mispadu

According to ESET Research, Mispadu is an ambitious Latin American banking trojan that utilizes McDonald’s malvertising and extends its attack surface to web browsers.

MALWARE

Banking

11.02.23

PixPirate

That said, on top of this evolution, one of the most crucial elements which have been disrupting the current state-of-art of anti-fraud departments is Instant Payments. 

MALWARE

Banking Malware

20.01.23

ERMAC

On July 23 a forum post appeared regarding a new Android banking trojan. The attached screenshots show that it is named ERMAC

MALWARE

Banking Malware

20.01.23

BlackRock

Around May 2020 ThreatFabric analysts have uncovered a new strain of banking malware dubbed BlackRock that looked pretty familiar.

MALWARE

Banking Malware

09.04.22

Octo

 

MALWARE

Banking Malware

09.04.22

SharkBot

 

MALWARE

Banking Malware

08.05.22

Dridex

OxCERT blog describes Dridex as "an evasive, information-stealing malware variant

MALWARE

Banking Trojan

01.03.22

TeaBot

 

MALWARE

Banking/RAT Malware