ThaiCERT    ETDA    MDES
Report
Search
Home > List all groups > List all tools > List all groups using tool Fobber

Threat Group Cards: A Threat Actor Encyclopedia

Permanent link Tool: Fobber

NamesFobber
CategoryMalware
TypeBanking trojan, Backdoor, Credential stealer
Description(GovCERT.ch) In the original sample, there was no sign of Man-in-the-Browser (MitB) aiming to stealbanking credentials but, since the malware has the capability to update itself, this posibilitycan be later added by the attackers.On our analysis, apart from the update feature, we only found the form-grabbing / cookie-stealing malicious feature.
Information<https://www.govcert.admin.ch/downloads/whitepapers/govcertch_fobber_analysis.pdf>
<https://www.govcert.ch/blog/analysing-a-new-ebanking-trojan-called-fobber/>
<https://blog.malwarebytes.com/threat-analysis/2015/06/elusive-hanjuan-ek-caught-in-new-malvertising-campaign/>
<http://blog.wizche.ch/fobber/malware/analysis/2015/08/10/fobber-encryption.html>
<http://byte-atlas.blogspot.ch/2015/08/knowledge-fragment-unwrapping-fobber.html>
<https://searchfinancialsecurity.techtarget.com/news/4500249201/Fobber-Drive-by-financial-malware-returns-with-new-tricks>
Malpedia<https://malpedia.caad.fkie.fraunhofer.de/details/win.fobber>
AlienVault OTX<https://otx.alienvault.com/browse/pulses?q=tag:Fobber>

Last change to this tool card: 24 May 2020

Download this tool card in JSON format

Previous: FlyingDutchman
Next: Foozer

All groups using tool Fobber

ChangedNameCountryObserved

Unknown groups

X_[ Interesting malware not linked to an actor yet ]_ 

1 group listed (0 APT, 0 other, 1 unknown)

Thailand Computer Emergency Response Team (ThaiCERT)
Electronic Transactions Development Agency

Follow us on

Facebook Twitter

Report incidents

Telephone +66 (0)2-123-1234
E-mail report@thaicert.or.th
PGP Download PGP key