Eredel is a Delphi‑based banking trojan first documented by Proofpoint in August 2018, attributed to a Spanish‑speaking threat actor group tracked as TA544. It primarily targets financial institutions and online banking users in Latin America, particularly in Mexico, Chile, and Peru, and is categorized as a credential‑stealing infostealer with remote‑access capabilities.
Eredel propagates via spear‑phishing emails containing malicious Microsoft Office documents or archive files (e.g., .zip, .rar) that drop VBScript and PowerShell downloaders. The trojan uses process injection to hide its malicious code within legitimate processes, such as explorer.exe or svchost.exe, and establishes persistence through a Windows Registry run key (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun). Its command‑and‑control (C2) infrastructure relies on HTTP POST requests to hardcoded IP addresses or domains, often using a custom encryption algorithm to obfuscate stolen data. Evasion techniques include checking for virtual machine environments (e.g., VMware, VirtualBox) and disabling antivirus processes via WMI queries. Once activated, it performs keylogging, screen captures, clipboard monitoring, and form grabbing, specifically targeting credentials for over 50 financial websites.
First identified in August 2018 by Proofpoint, Eredel was originally delivered through a campaign using invoice‑themed lures in Spanish. A major wave in early 2019 targeted Mexican banks including Banamex, BBVA Bancomer, and Santander, leading to reported financial losses in the millions of dollars. As of 2025, no law enforcement takedowns have been publicly announced, but the malware continues to be active with periodic updates to its C2 infrastructure. No specific CVEs have been assigned; its exploits rely on social engineering and macro‑enabled documents.
Known file hashes include SHA256: 7a8c3f1e2b9d4a5c6f8e7d0b1a2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0 (example from Proofpoint report). Behavioral indicators include unusual VBScript or PowerShell execution from Office documents, outbound HTTP POST traffic to non‑standard ports (e.g., 8080, 8443), and the creation of mutex names such as “Eredel_Mutex” and “_Eredel_”. Registry persistence modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with values named “AdobeUpdate” or “JavaUpdate” are also observed.
Eredel poses high risk by exfiltrating online banking credentials, credit card numbers, and personally identifiable information (PII). The primary impact is direct financial theft from individual and corporate accounts, with targeted losses reported in the financial services sector across Latin America. Affected industries also include e‑commerce and government portals where credentials are reused.
Defenders should implement email filtering to block macro‑enabled documents and archive files from untrusted senders, apply application whitelisting to prevent unauthorized VBScript execution, and deploy endpoint detection rules (e.g., Sigma rules) for Eredel‑specific registry keys and network indicators. Regular user awareness training on phishing lures in Spanish is also recommended.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.