Deep Dive: Spyeye (Banking_Trojan)
Today we are analyzing the Spyeye malware family, which falls under the Banking_Trojan category.
Overview
SpyEye is a banking Trojan that originated in Russia and was sold on underground forums for several hundred dollars, marketed as "the next Zeus." It targeted web browsers on Microsoft Windows (and Safari on Apple iOS) and provided the typical capabilities of a banking Trojan, including keylogging, automatic credit-card form filling, encrypted configuration files, email backups, and POP3 and FTP credential grabbers. SpyEye allowed criminals to steal money from online bank accounts and to initiate fraudulent transactions even while a legitimate user was logged in. It is documented by Fraunhofer FKIE's Malpedia.
Frequently Asked Questions
What is SpyEye?
SpyEye is a banking Trojan that originated in Russia and was sold on underground forums, marketed as "the next Zeus." It was designed to steal money from victims' online bank accounts.
What can SpyEye do?
SpyEye includes capabilities typical of banking Trojans: keylogging, automatic credit-card form filling, encrypted configuration files, email backups, and POP3 and FTP credential grabbers.
How does SpyEye steal money?
SpyEye targets web browsers to capture banking credentials and can initiate fraudulent transactions even while a legitimate user is logged into their bank account.
What sources document SpyEye?
SpyEye is profiled in Fraunhofer FKIE's Malpedia, which describes its origin, pricing on underground forums, and its banking-Trojan capabilities.
This article is part of the Malware Families Catalog. Visit the original page for more details and interactive data! You can also find the full dataset on Hugging Face and Kaggle.
Top comments (0)