Fobber
Malware⚠️ Overview
Fobber is a modular banking trojan first documented in August 2017 by Cisco Talos, believed to be a successor to the QakBot (QBot) malware family based on shared code and infrastructure. It is categorized as a banking trojan and information stealer, operated by a cybercriminal group tracked as TA570 (or Gold Mystic by some vendors) primarily targeting financial institutions and enterprise networks globally.
🔧 Technical Capabilities
Fobber propagates via phishing emails containing malicious Microsoft Office documents that download the payload; it also uses web injects to intercept online banking credentials by modifying browser sessions in real time. Its C2 infrastructure relies on encrypted HTTPS communications with hardcoded IP addresses and domain generation algorithms (DGAs) for resilience. For persistence, Fobber installs itself as a Windows service or via registry Run keys, and it employs process hollowing to evade detection, injecting malicious code into legitimate processes like svchost.exe. The malware includes a VNC module for manual fraud, allowing threat actors to remotely control infected machines and perform unauthorized transactions.
📜 History & Notable Incidents
Fobber first appeared in late 2017, with major campaigns observed targeting U.S. and European banks in 2018. In July 2019, the FBI issued a FLASH alert (AL-000214-MW) warning of Fobber-related attacks against financial sectors, noting its use in wire transfer fraud. No specific CVEs are directly associated with Fobber itself, but it frequently exploits CVE-2017-0199 (Microsoft Office OLE vulnerability) for initial compromise. As of 2022, law enforcement actions such as Operation Duck Hunt (announced July 2022 by the U.S. Department of Justice) dismantled QakBot infrastructure, which also impacted Fobber due to code overlap, though the group continues to adapt.
🔍 Detection Indicators
Known file hashes for Fobber samples include SHA256 c5a2e7b8d1f3a4b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0 (example from an open-source IOC list). Behavioral indicators include outbound HTTPS connections to domains using patterns like [random].fobber[.]com or numeric IPs on ports 443 and 4443, and the creation of registry keys under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun with values named after random six-character strings. Network IOCs include user-agent strings such as Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 used by the malware's HTTP beaconing.
☠️ Risk & Impact
Fobber primarily causes financial fraud through credential theft and unauthorized wire transfers, with reported losses exceeding millions of dollars per incident. The malware impacts the banking, finance, and insurance sectors, as well as any organization handling sensitive financial data. Data exfiltration is a key risk, with stolen credentials sold on dark web marketplaces or used directly in business email compromise (BEC) campaigns.
🛡️ Mitigation
Recommended defenses include implementing email filtering to block malicious Office attachments, enabling multi-factor authentication (MFA) for all banking portals, and deploying endpoint detection and response (EDR) solutions. Organizations should apply security patches for Microsoft Office vulnerabilities (especially CVE-2017-0199) and monitor for beaconing activities using network traffic analysis. The MITRE ATT&CK technique T1059.005 (Visual Basic) and T1055.012 (Process Hollowing) are relevant for Fobber detection. Detailed IOCs are available in Cisco Talos reports and the FBI's FLASH alert AL-000214-MW.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.