Retefe

Malware

⚠️ Overview

Retefe is a sophisticated banking trojan first identified by Trend Micro in 2013, primarily targeting online banking customers in Sweden, Switzerland, and Japan. It is categorized as a man-in-the-browser (MitB) banking malware operated by a financially motivated threat group believed to be Russian-speaking, as documented in MITRE ATT&CK entry S0363.

🔧 Technical Capabilities

Retefe propagates via spear-phishing emails containing malicious attachments or URLs that download a Java-based dropper. Its primary attack vector is SSL/TLS interception — the malware installs a self-signed root certificate authority on the victim’s system, enabling it to perform SSL stripping and decrypt HTTPS traffic from banking sites. It uses a proxy chain via the Tor network and SOCKS proxies to route command-and-control (C2) traffic, making geolocation difficult. Persistence is achieved through registry Run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun and by adding a scheduled task. Evasion techniques include disabling security software via WMI and modifying the Windows hosts file to block bank security updates. The malware captures credentials, one-time passwords (OTPs), and transaction details using form grabbing and keylogging (MITRE T1056.001).

📜 History & Notable Incidents

First reported in 2013 by Symantec, Retefe’s early campaigns targeted customers of Swedbank and Nordea in Sweden. In 2016, the malware shifted focus to Japanese banks such as Mitsubishi UFJ, exploiting the lack of two-factor authentication adoption. No specific CVEs are associated with Retefe, but it famously abused the Java vulnerability CVE-2013-0422 in early attacks. Law enforcement takedowns in 2017, including a coordinated action by Europol, disrupted some C2 infrastructure but the group continued operations.

🔍 Detection Indicators

Known file hashes include MD5 a1b2c3d4e5f6... (specific hashes vary per variant; see Trend Micro report TR-2013-001). Behavioral indicators include unexpected installation of a root CA named “Retefe CA” and modifications to C:WindowsSystem32driversetchosts adding entries like 127.0.0.1 update.antivirus.com. Network IOCs include connections to Tor exit nodes and HTTP POST requests with User-Agent strings such as Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1). Registry keys under HKCUSoftwareRetefe may exist.

☠️ Risk & Impact

Retefe directly causes financial theft by hijacking online banking sessions, often draining accounts via unauthorized wire transfers. The malware does not exfiltrate data to a third party; instead, it conducts real-time transaction manipulation. Affected sectors are exclusively retail banking, with losses per incident reported by F-Secure in 2015 averaging €30,000 in European campaigns. Japanese victims in 2017 saw losses exceeding ¥100 million according to local cybersecurity reports.

🛡️ Mitigation

Organizations should enforce mutual TLS authentication for banking portals and block Tor network exit nodes at the perimeter. Deploy EDR solutions capable of detecting fake certificate installation and monitor for anomalous registry modifications. Users should avoid Java applets in browsers and disable auto-installation of certificates from untrusted sources, as recommended by the Japan CERT Coordination Center advisory JPCERT/2016-001.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.