View all newsletters
Receive our newsletter - data, insights and analysis delivered to you
  1. Technology
  2. Cybersecurity
December 11, 2015

Whatsapp lures users to banking Trojan on Google cloud servers

News: Newly found attack targets Brazil.

By Charlotte Henry

Zscaler has identified a new Spy Banking Trojan which is using Google Cloud Servers, and targeting Portuguese speakers in Brazil.

The cyber security firm says that Google Cloud Servers are used to host the initial Spy Banker Downloader Trojan, which then installs the Spy Banker Trojan Telax.

The attackers are luring users to download and install the malicious payload via social engineering techniques, offering coupon vouchers and software like popular messaging app WhatsApp, and antivirus software tool Avast.

Social media is being used to spread a bit.ly shorted URL that points to the server hosting the malicious payload, says the firm: "The attack starts with a shortened URL posted on a social networking site or via drive by download from malicious sites posing to offer premium software or coupons."

That shortened link sends users to a PHP file hosted on a Google Cloud Server that redirects to the initial Spy Banker Downloader Trojan payload.

An executable file named receitanet.com is pretending to be Brazil’s federal revenue online tax returns service, and other themes offering fake premium software applications and discount vouchers also exist via differently named files.

Zscaler says "that Google has already cleaned up the cloud servers being currently redirected by these two active sites and hence the infection cycle will fail with a 404 Not Found message."

Content from our partners
An evolving cybersecurity landscape calls for multi-layered defence strategies
Powering AI’s potential: turning promise into reality
Unlocking growth through hybrid cloud: 5 key takeaways

Websites in our network
Select and enter your corporate email address Tech Monitor's research, insight and analysis examines the frontiers of digital transformation to help tech leaders navigate the future. Our Changelog newsletter delivers our best work to your inbox every week.
  • CIO
  • CTO
  • CISO
  • CSO
  • CFO
  • CDO
  • CEO
  • Architect Founder
  • MD
  • Director
  • Manager
  • Other
Visit our privacy policy for more information about our services, how Progressive Media Investments may use, process and share your personal data, including information on your rights in respect of your personal data and how you can unsubscribe from future marketing communications. Our services are intended for corporate subscribers and you warrant that the email address submitted is your corporate email address.
THANK YOU