Skip to content

Malware

Retefe

aka Tsukuba · Werdlod

Retefe is a Windows Banking Trojan that can also download and install additional malware onto the system using Windows PowerShell.

Retefe, also known as Tsukuba, Werdlod, is a Windows malware family.

Background

Retefe is a Windows banking trojan that is also capable of pulling down and installing further malware through Windows PowerShell. Its main goal is to help attackers steal online banking credentials, and it has predominantly been aimed at Swiss banks. The binary itself acts mostly as a dropper for a JavaScript file, which in turn assembles a VBA file that fetches several tools onto the host, including 7zip and TOR. That VBA component adds a new root certificate and routes all traffic through TOR to an attacker-controlled host, enabling an effective man-in-the-middle on TLS traffic.


Source: Malpedia (Fraunhofer FKIE).