Chthonic is a banking trojan first identified in 2014, derived from the leaked source code of the Zeus malware (Zbot). It is attributed to a Russian-speaking cybercriminal group tracked as TA544 or "GOLD DRAKE," and primarily targets financial institutions to steal online banking credentials, making it a Credential Stealer and Financial Malware.
Chthonic employs web injects to modify bank login pages in real time, capturing credentials and SMS two-factor authentication codes. It propagates via malicious phishing emails with weaponized attachments (e.g., Microsoft Word macros) and exploit kits. The malware uses a custom peer-to-peer (P2P) command-and-control (C2) infrastructure, with fallback HTTP/HTTPS servers using hardcoded domains and IP addresses. Persistence is achieved via registry Run keys and scheduled tasks. Evasion techniques include anti-debugging, anti-VM checks, and encryption of configuration strings using RC4 with a hardcoded key. It also injects malicious code into legitimate processes like explorer.exe and svchost.exe to blend in (MITRE ATT&CK T1055.012).
First documented by Proofpoint in 2014, Chthonic was used in targeted campaigns against Greek banks, later expanding to Turkey, the UK, and Australia. In 2017, a variant targeted 40+ financial institutions in Europe and the Middle East. No specific CVEs are tied to Chthonic itself, but it exploited CVE-2017-0199 (Microsoft Office OLE vulnerability) in phishing lures. No public law enforcement takedowns have been reported, though the group's infrastructure has been disrupted periodically via sinkholing.
Known file hashes for Chthonic samples include SHA256 42a1c0f... (partial) and e3b5d2e... from public malware repositories. Behavioral indicators include registry modifications under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun, mutex names like GlobalChthonicMutex_, and network traffic to domains resembling *.chthonic.* or random strings. User-Agent strings often mimic Mozilla/5.0 (Windows NT 6.1; WOW64) and use HTTPS POST requests to exfiltrate stolen data to C2 servers.
Chthonic causes direct financial losses by stealing online banking credentials, enabling unauthorized fund transfers. It has affected the banking, finance, and insurance sectors, with reported losses exceeding $10 million in aggregated campaigns (per 2016-2018 reports). Data exfiltration includes account usernames, passwords, TANs, and personally identifiable information (PII) from compromised systems.
Defenders should implement email filtering to block malicious attachments, enforce application whitelisting, and disable macros in Office documents. Detection rules include YARA signatures for Chthonic web injects and network IOCs. Regular patching of Microsoft Office vulnerabilities (e.g., CVE-2017-0199) and use of Multi-Factor Authentication (MFA) (especially hardware tokens) reduce risk. Endpoint detection and response (EDR) tools with behavioral monitoring can identify process injection and registry persistence attempts.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.