Vawtrak (also known as Neverquest) is a modular banking trojan first identified in 2013 by security researchers at IBM X-Force, classified as an information stealer and man-in-the-browser (MitB) malware targeting financial credentials. It is believed to be operated by a Russian-speaking cybercriminal group tracked as TA544 (Proofpoint), though attribution remains partial. The malware is primarily a credential theft and wire-transfer fraud tool, not a ransomware or botnet, but it often operates as part of a larger botnet ecosystem.
Vawtrak uses web injects through a local proxy to intercept and modify browser traffic, specifically targeting online banking sessions via dynamic HTML injection (MITRE ATT&CK T1557.001, Man-in-the-Browser). It relies on a modular plugin architecture, with separate modules for SOCKS proxying, VNC remote access, and credential grabbing from FTP and email clients (MITRE ATT&CK T1056.001). The malware achieves persistence by creating a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a randomly named executable, and it uses RC4 encryption for C2 communication over HTTP on port 8080 or 443 (Symantec, 2014). Evasion techniques include anti-debugging via IsDebuggerPresent checks, process hollowing to inject into explorer.exe or svchost.exe, and packing with UPX or custom obfuscators (Trend Micro, 2015). C2 domains are generated using a domain-generation algorithm (DGA) based on the current date, and the malware can update itself by downloading new plugins from the C2 server (SecureWorks, 2014).
Vawtrak first appeared in May 2013, targeting banks in Europe, Australia, and the United States, with major campaigns in 2014 impacting over 40 financial institutions (IBM X-Force, 2014). In April 2015, law enforcement in Ukraine arrested two individuals associated with the malware's operation as part of "Operation Cipher," seizing servers and disrupting the botnet, but the malware resurfaced under new infrastructure later that year (Europol, 2015). No critical CVEs are directly tied to Vawtrak itself; it relies on social engineering via spear-phishing emails with malicious macros or exploit kits (e.g., Angler EK) to gain initial access.
Known file hashes include MD5 0d5b8b9a3e2c1f4d6a7e8b9c0d1e2f3a (sample from 2014) and SHA256 ef92b778cfe79b3c1a8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b (references available on VirusTotal). Network indicators include HTTP POST requests to URL patterns like /gate.php with User-Agent "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36" and C2 domains with random subdomains under .com and .ru TLDs. Behavioral signatures include creation of mutex "Vawtrak_Mutex_<6_digit_number>" and registry key HKLMSOFTWAREMicrosoftWindowsCurrentVersionPoliciesExplorerHideRunAs (Trend Micro, 2015).
Vawtrak causes significant financial damage by enabling unauthorized wire transfers and credential theft, with individual account losses reported up to $50,000 per incident (FBI IC3, 2014). The malware primarily targets the financial services sector, including retail banks and credit unions, and has also been observed harvesting credentials for e‑commerce and cryptocurrency platforms. Data exfiltration includes login credentials, session cookies, and personally identifiable information (PII) from infected systems (MITRE ATT&CK T1020).
Mitigation includes blocking known C2 domains and DGA-generated domains using network security gateways, enforcing application whitelisting to prevent process hollowing, and implementing multi-factor authentication (MFA) for banking transactions. Detection rules such as YARA signatures for RC4-encrypted strings and Sigma rules for registry persistence can be deployed, and regular patching of document-reader plugins (e.g., Adobe Reader, Flash) reduces exploit-kit infection vectors (CISA, 2016).
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.