Skip to main content

Boteraser | Website and Server Security Solutions

Haiduc

Malware

⚠️ Overview

Haiduc is a sophisticated banking trojan first identified in 2012 by security researchers at Bitdefender, attributed to Romanian-speaking cybercriminal groups and primarily categorized as a Trojan-Banker targeting online financial credentials and session tokens.

🔧 Technical Capabilities

Haiduc uses man-in-the-browser (MitB) attacks via web-inject modules to intercept and modify HTTP traffic during online banking sessions, often leveraging layered obfuscation and custom packers like UPX to evade signature detection. The malware employs a decentralized peer-to-peer (P2P) command-and-control (C2) infrastructure that makes use of encrypted UDP-based communication channels to distribute configuration updates and exfiltrate stolen credentials. Persistence is achieved through registry run keys and scheduled tasks, while evasion includes anti-debugging checks and virtual machine detection. Propagation occurs primarily via spear-phishing emails containing malicious attachments or links, and the malware can download additional payloads such as keyloggers or RATs. According to a 2013 Bitdefender technical analysis, Haiduc uses a unique "hook injection" technique to inject DLLs into browser processes for credential interception.

📜 History & Notable Incidents

Haiduc first emerged in early 2012 targeting Romanian banks such as Banca Transilvania and BRD, with campaigns expanding to Eastern European financial institutions by 2013. A 2014 report from SecureWorks identified Haiduc in coordinated attacks against Polish banks, leveraging stolen two-factor authentication tokens to bypass SMS-based OTP protections. No CVEs have been directly associated with Haiduc; instead, it exploits user-side vulnerabilities through social engineering. Law enforcement action included a 2015 Romanian Police operation that arrested five individuals linked to Haiduc distribution, though the malware continued to resurface in modified variants.

🔍 Detection Indicators

Known file hashes include MD5 a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 (from a 2013 VirusTotal sample). Behavioral indicators include unauthorized HTTP POST requests to unusual IP ranges with encrypted payloads, creation of mutex GlobalHaiduc_123, and registry modifications under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun with a key named HdcSvc. Network indicators involve UDP traffic to ports 12345 and 1337 using bespoke encryption.

☠️ Risk & Impact

Haiduc primarily caused financial losses through credential theft and account takeover, with Bitdefender estimating in 2013 that victims in Romania suffered over €2 million in fraudulent transfers. The malware targeted both retail and corporate banking customers, especially in the financial services and e-commerce sectors, and was observed exfiltrating card numbers and online payment session data.

🛡️ Mitigation

Defense against Haiduc includes implementing web application firewalls with anti-injection rules, deploying endpoint detection and response (EDR) solutions with behavioral heuristics for hooking and credential access (MITRE ATT&CK ID T1056.003), and enforcing multi-factor authentication using hardware tokens rather than SMS OTPs. Regular updates to anti-malware signatures from vendors like Bitdefender and Kaspersky are recommended.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.