Warning: Hesperbot taking aim at Europe and Asia

Updated happygeek 2 Tallied Votes 409 Views Share

Users of online banking services are at risk from a new 'in the wild' Trojan, Hesperbot, which has been discovered by the ESET malware research lab.

Researchers have found that infections of users in Turkey are currently most rife, with users in the Czech Republic, Portugal, Thailand and the United Kingdom also falling victim along with smatterings elsewhere. Victims in the Czech Republic, so it would seem, have been hardest in terms of financial loss with ESET claiming that people hit by Hesperbot in this region have "lost significant amounts of money as a result".

Hesperbot is spread using very credible looking phishing emails, with the primary aim of accessing bank accounts and a secondary one of attempting to install a mobile component of the malware on mobile devices running Android, Blackberry or Symbian operating systems.

Hesperbot appears to be quite a sophisticated piece of malware. Although it has the kind of key logger capabilities, desktop screen shot and video capture functionality and remote proxy set-up that you might expect of any self-respecting malware these days, Hesperbot goes the extra mile as it were. Additional tricks include creating a hidden VNC server on the infected system, and the addition of network traffic interception and HTML injection capabilities.

Researchers say that while the functionality is similar to Zeus or SpyEye, both banking Trojans that have been around for some time, Hesperbot introduces significant implementation differences and as such is a brand new malware family rather than just a new variant of an old theme.

Not everything about Hesperbot is new though, take the phishing campaign being used to spread it for example. Robert Lipovsky, the ESET malware researcher who is leading the team analyzing it, explains that in the Czech Republic, for example, the people behind the malware registered a domain that was very similar to the official Czech Postal Service site and used credible looking parcel tracking notification emails to lure people in. However, different regions have been targeted with different phishing scams: in Turkey, where the known infection rate is highest, a fake invoice scam was used.

Full technical details and analysis can be found at the ESET 'We Live Security' site.

e52576f388626d404fe8d104b924e737

ss125 commented: Thanks for the info!!! +3

Dani AI

Generated

’s post points to important research on a banking‑trojan campaign; this short addendum focuses on practical, evergreen steps for IT teams and for customer-facing teams (good point, ). The guidance below avoids repeating the original technical writeup and instead gives clear incident, containment and prevention actions that apply to Hesperbot‑style banker threats and similar phishing campaigns. (kaspersky.com)

Immediate response checklist for a suspected infection:

  • Isolate the endpoint from the network (physically unplug or disable Wi‑Fi) but preserve evidence if you intend to do forensic capture (collect memory/logs first if you can).
  • If you do not have forensics skills, quarantine and reimage the host from a trusted backup.
  • From a known‑clean device, reset all credentials that may be exposed and enable strong MFA. Notify the affected bank(s) immediately and follow their fraud procedures.
  • Collect basic IoC information (filenames, suspicious domains, timestamps) and share with your SOC/CSIRT. Follow an established IR playbook (triage → contain → eradicate → recover → lessons learned). (lewiscreeksystems.com)

Hardening and prevention (short list of high‑value controls):

  • Enforce phishing‑resistant MFA for banking and high‑privilege accounts (prefer hardware tokens or FIDO/passkeys over SMS where possible).
  • Use endpoint detection/response with behavioral rules and block risky attachments via sandboxing.
  • Apply email authentication (SPF/DKIM/DMARC), web‑filtering, network segmentation, and least‑privilege for admin accounts. Keep OS and apps patched. Regular phishing training with simulated tests reduces click rates. (npsa.gov.uk)

Short client‑alert template (copy, shorten for your brand):

  • “Do not open unexpected attachments or links. If you think you clicked one, do not enter credentials and contact us immediately. Change your passwords from a different device and enable two‑factor authentication. If you see unauthorized transactions, contact your bank right away.”
    Advise customers to report fraud and forward suspicious emails to your security team or national reporting body so indicators can be shared. (cisa.gov)

Caution: when in doubt engage incident‑response professionals; improper cleanup can leave backdoors active.

ss125 18 Posting Whiz in Training

Nice Information... Since I am related to financial domain(eventhough our clients are not from the above mentioned location) we can atleast provide an alert regarding this information to ur clients..

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.