Skip to content

Banking Trojan

Risk Level

Banking trojans are specialised malware designed to steal financial credentials and conduct fraudulent transactions. They use overlay attacks, form grabbing, webinjects, and SMS interception to bypass 2FA.

MilestoneYearDetails
Zeus/Zbot2007First major banking trojan; $100M+
SpyEye2009Competitor; form grabbing
Citadel2011Zeus fork; modular
Gameover Zeus2011P2P C2; 1M+ infections
Dridex2014Macro delivery; corporate banking
TrickBot2016Modular; banking → ransomware
Emotet2014+Loader → banking → ransomware
IcedID2017Loader → banking → ransomware
Qakbot2007+Banking → ransomware delivery
TechniqueDescription
Overlay AttackFake login screen over legitimate banking app
Form GrabbingHook browser APIs (PR_Read, etc.) pre-encryption
WebinjectsInject HTML/JS into banking pages
Form GrabbingHook PR_Read, PR_Write, SSL_Read
SMS InterceptionForward 2FA codes to attacker
Accessibility AbuseAndroid: BIND_ACCESSIBILITY_SERVICE
VNC/RATRemote view/control for transaction auth
FamilyPlatformYearNotable
Zeus/ZbotWindows2007$100M+; source leaked
SpyEyeWindows2009Form grabbing
CitadelWindows2011Zeus fork; modular
Gameover ZeusWindows2011P2P C2; 1M+
DridexWindows2014Corporate banking; macros
TrickBotWindows2016Modular; → ransomware
EmotetWindows2014+Loader platform
IcedIDWindows2017Loader → ransomware
QakbotWindows2007+Banking → ransomware
AnubisAndroid2017+Overlay, SMS, RAT
CerberusAndroid2019+Overlay, RAT, keylog
EventBotAndroid2020Accessibility abuse
  • FIDO2/WebAuthn — Phishing-resistant, no passwords
  • Password Manager — Auto-fill bypasses keyloggers/form grabbers
  • Transaction Verification — Out-of-band (push, SMS not sufficient)
  • App Hardening — Anti-tamper, root detection, emulator detection
  • EDR — Detect overlay, accessibility abuse, form grabbing
  • Transaction Signing — Hardware token, FIDO2, mobile app
  • App Attestation — Play Integrity / DeviceCheck
TechniqueIDDescription
Input CaptureT1056Keylogging, form grabbing
Web Session CookieT1550.004Session hijacking
Multi-Factor Authentication InterceptionT1111SMS intercept