Javali

S0528

Malware.View on attack.mitre.org

About this malware

Javali is a banking trojan that has targeted Portuguese and Spanish-speaking countries since 2017, primarily focusing on customers of financial institutions in Brazil and Mexico.

Techniques used12

Procedure examples12

TechniqueProcedure example
T1027.001
Binary Padding

Javali can use large obfuscated libraries to hinder detection and analysis.

T1057
Process Discovery

Javali can monitor processes for open browsers and custom banking applications.

T1059.005
Visual Basic

Javali has used embedded VBScript to download malicious payloads from C2.

T1102.001
Dead Drop Resolver

Javali can read C2 information from Google Documents and YouTube.

T1105
Ingress Tool Transfer

Javali can download payloads from remote C2 servers.

T1204.001
Malicious Link

Javali has achieved execution through victims clicking links to malicious websites.

T1204.002
Malicious File

Javali has achieved execution through victims opening malicious attachments, including MSI files with embedded VBScript.

T1218.007
Msiexec

Javali has used the MSI installer to download and execute malicious payloads.

T1555.003
Credentials from Web Browsers

Javali can capture login credentials from open browsers including Firefox, Chrome, Internet Explorer, and Edge.

T1566.001
Spearphishing Attachment

Javali has been delivered as malicious e-mail attachments.

T1566.002
Spearphishing Link

Javali has been delivered via malicious links embedded in e-mails.

T1574.001
DLL

Javali can use DLL side-loading to load malicious DLLs into legitimate executables.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Securelist Brazilian Banking Malware July 2020 Open source
    GReAT. (2020, July 14). The Tetrade: Brazilian banking malware goes global. Retrieved November 9, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.