
Banking trojans are specialised malware designed to steal financial credentials and conduct fraudulent transactions. They use overlay attacks, form grabbing, webinjects, and SMS interception to bypass 2FA.
| Milestone | Year | Details |
|---|
| Zeus/Zbot | 2007 | First major banking trojan; $100M+ |
| SpyEye | 2009 | Competitor; form grabbing |
| Citadel | 2011 | Zeus fork; modular |
| Gameover Zeus | 2011 | P2P C2; 1M+ infections |
| Dridex | 2014 | Macro delivery; corporate banking |
| TrickBot | 2016 | Modular; banking → ransomware |
| Emotet | 2014+ | Loader → banking → ransomware |
| IcedID | 2017 | Loader → banking → ransomware |
| Qakbot | 2007+ | Banking → ransomware delivery |
| Technique | Description |
|---|
| Overlay Attack | Fake login screen over legitimate banking app |
| Form Grabbing | Hook browser APIs (PR_Read, etc.) pre-encryption |
| Webinjects | Inject HTML/JS into banking pages |
| Form Grabbing | Hook PR_Read, PR_Write, SSL_Read |
| SMS Interception | Forward 2FA codes to attacker |
| Accessibility Abuse | Android: BIND_ACCESSIBILITY_SERVICE |
| VNC/RAT | Remote view/control for transaction auth |
| Family | Platform | Year | Notable |
|---|
| Zeus/Zbot | Windows | 2007 | $100M+; source leaked |
| SpyEye | Windows | 2009 | Form grabbing |
| Citadel | Windows | 2011 | Zeus fork; modular |
| Gameover Zeus | Windows | 2011 | P2P C2; 1M+ |
| Dridex | Windows | 2014 | Corporate banking; macros |
| TrickBot | Windows | 2016 | Modular; → ransomware |
| Emotet | Windows | 2014+ | Loader platform |
| IcedID | Windows | 2017 | Loader → ransomware |
| Qakbot | Windows | 2007+ | Banking → ransomware |
| Anubis | Android | 2017+ | Overlay, SMS, RAT |
| Cerberus | Android | 2019+ | Overlay, RAT, keylog |
| EventBot | Android | 2020 | Accessibility abuse |
- ✅ FIDO2/WebAuthn — Phishing-resistant, no passwords
- ✅ Password Manager — Auto-fill bypasses keyloggers/form grabbers
- ✅ Transaction Verification — Out-of-band (push, SMS not sufficient)
- ✅ App Hardening — Anti-tamper, root detection, emulator detection
- ✅ EDR — Detect overlay, accessibility abuse, form grabbing
- ✅ Transaction Signing — Hardware token, FIDO2, mobile app
- ✅ App Attestation — Play Integrity / DeviceCheck
| Technique | ID | Description |
|---|
| Input Capture | T1056 | Keylogging, form grabbing |
| Web Session Cookie | T1550.004 | Session hijacking |
| Multi-Factor Authentication Interception | T1111 | SMS intercept |