Lurk

Malware

⚠️ Overview

The Lurk malware family is a financial Trojan targeting online banking credentials, first documented by Kaspersky Lab in 2011. It is operated by a Russian-speaking threat group often referred to as the Lurk Group, which was the subject of a high-profile crackdown by the Russian Federal Security Service (FSB) in 2016. Lurk is classified as a banking trojan and web injector, specifically designed to steal authentication data and conduct automated fraudulent transactions via man-in-the-browser (MitB) attacks.

🔧 Technical Capabilities

Lurk uses web injection to intercept and modify HTTP traffic between the victim’s browser and legitimate banking websites, enabling real‑time credential theft and transaction fraud. It propagates via spear‑phishing emails containing malicious Microsoft Office documents or exploit kits, after which it establishes persistence through registry run keys and scheduled tasks. The malware employs a peer‑to‑peer (P2P) command‑and‑control (C2) infrastructure that leverages encrypted HTTP and HTTPS communications, often routing traffic through compromised web servers to evade detection. Evasion techniques include anti‑debugging checks, dynamic API resolution, and code obfuscation using custom packers. Lurk also installs a proxy component on infected machines to create a residential proxy network that can be used for anonymized criminal activity. Notably, it injects malicious JavaScript into banking sessions to modify transaction amounts or redirect funds to attacker‑controlled accounts.

📜 History & Notable Incidents

Lurk first appeared in 2011, primarily targeting Russian financial institutions. In June 2016, the Russian FSB arrested 50 individuals linked to the Lurk Group, claiming they had stolen over 1.7 billion rubles (~$27 million USD) from Russian banks over several years. A related campaign in 2014 exploited the vulnerability CVE‑2014‑6332 (Internet Explorer OLE Automation) to deliver the malware via drive‑by downloads. No other high‑profile CVEs are exclusively tied to Lurk, but it often leveraged zero‑day exploits available on underground markets.

🔍 Detection Indicators

Known file hashes for Lurk variants include SHA‑256 values such as 2c1c9a7b5d... (truncated) published in Kaspersky threat reports; however, exact hashes change with each packer version. Behavioral signatures include the creation of randomly named mutexes prefixed with Lurk or lurker, and registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun for persistence. Network IOCs include C2 domains using random‑generated subdomains on compromised legitimate websites, and HTTP requests with User‑Agent strings mimicking common browsers appended with custom parameters.

☠️ Risk & Impact

Lurk directly causes financial loss through unauthorized banking transactions and credential exfiltration; the 2016 arrests highlighted at least 1.7 billion rubles stolen from Russian banks. The malware has also been deployed against government agencies and e‑commerce platforms in Eastern Europe. Its proxy network component is rented to other cybercriminals, amplifying the broader risk of anonymized attack infrastructure.

🛡️ Mitigation

Recommended mitigations include deploying endpoint detection and response (EDR) solutions with behavioral analytics capable of detecting web injection hooks, applying timely patches for Internet Explorer and Microsoft Office vulnerabilities, and implementing network‑level blocking of known malicious C2 domains using threat intelligence feeds from vendors like Kaspersky and Group‑IB.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.