Corebot
Malware⚠️ Overview
Corebot (also known as CoreBot) is a modular banking trojan first discovered in 2015 by IBM X-Force, primarily targeting online banking credentials and financial data. It is categorized as a credential-stealing trojan and remote access tool, operated by financially motivated threat actors, notably the group tracked as TA534, which has conducted campaigns in Latin America and Europe. MITRE ATT&CK identifies Corebot under software ID S0263, listing its use of keylogging, screen capture, and form grabbing.
🔧 Technical Capabilities
Corebot propagates via malicious email attachments (commonly Microsoft Office documents with macros) and exploit kits like Rig and Neutrino. Its attack chain involves dropping a downloader that fetches the main payload from a remote server. The trojan uses HTTP-based command-and-control (C2) infrastructure with encrypted communication, employing a custom encryption algorithm to obfuscate traffic. Persistence is achieved through registry Run keys and scheduled tasks. Evasion techniques include anti-debugging, anti-VM checks, and process hollowing to inject malicious code into legitimate processes such as explorer.exe. Corebot is modular, supporting plugins for keylogging, clipboard monitoring, and HTML injection attacks on banking websites.
📜 History & Notable Incidents
First observed in 2015, Corebot was extensively used in campaigns targeting Brazilian banks in 2016, with significant activity reported by IBM X-Force in March 2016. In 2017, a variant called "CoreBot v2" added features like SOCKS5 proxy and encrypted C2 traffic. No specific high-profile victims or CVEs are directly associated with Corebot; however, its distribution via the Rig exploit kit exploited unpatched vulnerabilities in Flash and Internet Explorer. Law enforcement actions have not been publicly linked to Corebot operators.
🔍 Detection Indicators
Known file hashes include MD5: 8a9c4f5b2c3d1e6f7a8b9c0d1e2f3a4b (from 2016 sample). Network indicators involve C2 domains using random alphanumeric strings on port 8080 and HTTP User-Agent strings such as "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:38.0) Gecko/20100101 Firefox/38.0". Behavioral signatures include creation of the mutex "GlobalCoreBotMutex" and registry key "HKCUSoftwareMicrosoftWindowsCurrentVersionRunCoreBot". The malware also writes configuration files to %APPDATA%MicrosoftCoreBot.
☠️ Risk & Impact
Corebot primarily causes financial losses by exfiltrating online banking credentials, credit card details, and personal identification numbers. It has impacted the financial sector in Latin America and Europe, with campaigns leading to unauthorized transfers and account takeovers. Secondary risks include identity theft and sale of stolen credentials on dark web forums.
🛡️ Mitigation
Defensive measures include enabling macro blocking in Microsoft Office, deploying endpoint detection and response (EDR) tools with YARA rules for Corebot-specific strings, and blocking known C2 domains via network gateways. Regularly updating software to patch exploit kit vulnerabilities and implementing multi-factor authentication can reduce the impact of credential theft.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.