Skip to content

Malware

Karius

According to checkpoint, Karius is a banking trojan in development, borrowing code from Ramnit, Vawtrack as well as Trickbot, currently implementing webinject attacks only.

Karius is a Windows malware family.

Background

Check Point describes Karius as a still-evolving banking trojan that reuses code from Ramnit, Vawtrack, and Trickbot, and so far supports only webinject-style attacks.

Its architecture starts with an injector that loads an intermediate "proxy" module, which then loads the actual banker module.

Traffic to the c2 is sent as JSON and encrypted using RC4 with a hardcoded key.

The first version, seen in March 2018, embedded the webinjects directly in the binary, whereas later versions instead retrieved them from the c2.


Source: Malpedia (Fraunhofer FKIE).