Chthonic

- Andromedins - AndroKINS

References:
  • Chthonic: a new modification of ZeuS - 2014-12-18 - Securelist - Yury Namestnikov - Vladimir Kuskov - Oleg Kupreev Chthonic
  • More Reading:

  • CVE-2014-0569 (Flash Player) integrating Exploit Kit - 2014-10-21 - MDNC - Kafeine CVE-2014-0569 Chthonic Fiesta Angler Astrum Sweet Orange FlashPack RIG Magnitude KovCoreG Kovter
  • Threat Actors Using Legitimate PayPal Accounts To Distribute Chthonic Banking Trojan - 2016-07-26 - Proofpoint - Proofpoint Staff Chthonic AZORult
  • "FakeUpdates" campaign leverages multiple website platforms - 2018-04-10 - Malwarebytes - Jérôme Segura SocGholish js-GhoLoader Chthonic
  • Fake Updates campaign still active in 2019 - 2019-02-12 - SANS ISC - Brad Duncan SocGholish Chthonic js-GhoLoader
  • 2019-06-24 - Still finding #FakeUpdates traffic similar to Feb 2019 [...] Still seeing #Chthonic banking Trojan as the final payload - 2019-06-27 - Twitter - Brad Duncan SocGholish Chthonic
  • Head Fake: Tackling Disruptive Ransomware Attacks - 2019-10-01 - FireEye - Bryce Abdo - Brandan Schondorfer - Kareem Hamdan - Kimberly Goody - Noah Klapprodt - Matt Bromiley BitPaymer SocGholish Dridex Chthonic AZORult