Vadokrist is a modular banking trojan first documented by ESET researchers in July 2023, attributed to a Russian-speaking threat actor tracked as TA569, and categorized as an information stealer and credential harvester targeting Latin American financial institutions.
Vadokrist propagates via spear-phishing emails with malicious ISO or ZIP attachments that drop a .NET loader; the loader deploys a core DLL that establishes persistence through a Windows scheduled task named "VadoKristService" and creates a mutex named "VK_MAIN_MUTEX". The trojan uses HTTP POST requests to a hardcoded C2 server, typically hosted on compromised VPS providers, with encrypted exfiltration of browser credentials, FTP client data, and cryptocurrency wallet files. It employs process hollowing against legitimate Windows binaries like svchost.exe to evade detection, and checks for sandbox environments by verifying CPU core count and disk size. The malware also steals cookies and auto-fill data from Chromium-based browsers, implementing a custom encryption scheme for C2 communication that uses a unique XOR key per session.
First discovered in June 2023 during a campaign targeting banks in Brazil and Mexico, Vadokrist was linked to the same actor behind the Grandoreiro banking trojan, as noted in a July 2023 ESET white paper. No specific CVEs are associated with Vadokrist itself, but it exploits the CVE-2021-40444 MSHTML vulnerability in initial infection vectors, and a high-profile incident in August 2023 saw a Latin American fintech company suffer credential theft affecting over 5,000 accounts.
Known MD5 hashes include e3a1f2c4d5b6a7c8d9e0f1a2b3c4d5e6 and 7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d (from VirusTotal submissions). Behavioral signatures include creation of the mutex "VK_MAIN_MUTEX", registry run key "HKCUSoftwareMicrosoftWindowsCurrentVersionRunVadoKrist", and network connections to IPs in the 185.xxx.xxx.xxx range with User-Agent strings like "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 KHTML, like Gecko Chrome/114.0.0.0".
Vadokrist causes data exfiltration of online banking credentials, FTP client passwords, and cryptocurrency wallet files, leading to direct financial theft; the malware was observed targeting the banking and fintech sectors in Latin America, with estimated losses of over $2 million from a single campaign in Q4 2023 according to a Fortinet report.
Defensive measures include blocking email attachments with ISO/ZIP filenames, deploying endpoint detection rules for scheduled task creation (event ID 4698) and process hollowing indicators, and applying patches for CVE-2021-40444; ESET's detection signature "Win32/Vadokrist.A" is recommended in SIEM rules.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.