Demystifying Banking Trojans from Latin America

Botconf 2019
2023-04-24 | 16:30 – 17:00

Juraj Horňák 🗣 | Jakub Souček 🗣 | Martin Jirkal 🗣

At the end of 2018, it has been reported that Latin America suffers approximately 3.7 million cyber-attacks per day. Even the most well-known pieces of malware, such as TrickBot or Emotet, have their eyes set on this region. When it comes to malware that originates in those countries, the first thing that comes to mind are those infamous, huge, mostly Delphi-written banking trojans. These banking trojans have been our focus for over a year now. They are completely different from what is generally called a banking trojan and because their authors tend to copy from one another or from the same sources, all of them are very similar to each other. That is the main reason we see only generic detections. Our research started with identifying strong characteristics that allowed us to identify more than 10 new malware families among them…

