Malware.View on attack.mitre.org
Javali is a banking trojan that has targeted Portuguese and Spanish-speaking countries since 2017, primarily focusing on customers of financial institutions in Brazil and Mexico.
| Technique | Procedure example |
|---|---|
| T1027.001 Binary Padding |
Javali can use large obfuscated libraries to hinder detection and analysis. |
| T1057 Process Discovery |
Javali can monitor processes for open browsers and custom banking applications. |
| T1059.005 Visual Basic |
Javali has used embedded VBScript to download malicious payloads from C2. |
| T1102.001 Dead Drop Resolver |
Javali can read C2 information from Google Documents and YouTube. |
| T1105 Ingress Tool Transfer |
Javali can download payloads from remote C2 servers. |
| T1204.001 Malicious Link |
Javali has achieved execution through victims clicking links to malicious websites. |
| T1204.002 Malicious File |
Javali has achieved execution through victims opening malicious attachments, including MSI files with embedded VBScript. |
| T1218.007 Msiexec |
Javali has used the MSI installer to download and execute malicious payloads. |
| T1555.003 Credentials from Web Browsers |
Javali can capture login credentials from open browsers including Firefox, Chrome, Internet Explorer, and Edge. |
| T1566.001 Spearphishing Attachment |
Javali has been delivered as malicious e-mail attachments. |
| T1566.002 Spearphishing Link |
Javali has been delivered via malicious links embedded in e-mails. |
| T1574.001 DLL |
Javali can use DLL side-loading to load malicious DLLs into legitimate executables. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.