Back in 2020, a new banking trojan by the name of BBTok emerged into the digital landscape and was responsible for numerous attacks. And now it’s back.

Banks in Brazil and Mexico appear to be the main targets of BBTok’s new campaign, and it’s a variant which is far more powerful than any of its previous incarnations. Its main deceptive threat is that it is able to spoof the interfaces of 40 different banks in Brazil and Mexico. This means that it’s perfectly placed to harvest sensitive data. In particular, this new strain of BBTok is deceiving victims into disclosing their credit card details and authentication codes. This gives the campaign a financial angle and highlights the serious threat it poses.

How Does BBTok Launch Its Attacks?

BBTok’s latest strategy begins with a phishing email, one that contains a malicious link which kickstarts the attack by launching the malware alongside a dummy document. BBTok is particularly successful as it has been coded to deal with multiple versions of Windows, and it also tailors the content of the attack to both the victim’s country and operating system. BBTok also allows the threat actors behind it to execute remote commands and steal data without the victim being aware.

Most notably, however, is the way in which BBTok replicates the interface of numerous banking websites – such as Citibank and HSBC – to truly deceive the victim. Appearing to be genuine at first glance, these interfaces are used to trick victims into entering security codes and passwords associated with their accounts. This gives the threat actors full access to their financial data and, more disturbingly, full control over their finances. This means that unauthorized payments and bank transfers can quickly land the victim in severe financial trouble.

How to Stay Safe from Banking Malware

In an increasingly digital world, where we all make numerous financial transactions online every week, it’s important to remain guarded against banking malware. As well as the financial damage that malware such as BBTok can cause, it can also create a foothold for threat actors to delve deep into your networks. And this represents a major threat to the security of both your data and your customer’s data. Accordingly, you need to stay safe, and here are some crucial tips to help you:

For more ways to secure and optimize your business technology, contact your local IT professionals. 

Read More


The only thing worse than a powerful piece of malware, is a powerful piece of malware which has evolved into something more dangerous, just like IcedID.

IcedID first emerged onto the digital landscape in 2017, when it was classed as a banking trojan and started targeting financial institutions in the US, Canada, and UK. IcedID’s main objective, in 2017, was to steal sensitive data such as credit card details. However, the very best threat actors are those that regularly update and repurpose their malware to evade detection and become more effective. And that’s exactly what they have done with IcedID, turning it from a banking trojan into something much more complex.

What is IcedID’s New Strategy?

IcedID has evolved, but what exactly has it evolved in to? Well, the objective of retrieving sensitive financial details appears to have been removed. However, IcedID is now concentrating its efforts on delivering further malicious payloads to compromised systems. Essentially, it’s opening your IT systems up to a whole new world of pain.

Using the BackConnect module, IcedID communicates with a command-and-control server which allows the transfer of commands and files to the infected system. Originally, this attack was easy to detect as IcedID used TCP port 8080 to transfer data and communications. However, the threat actors behind this new wave of attacks, quickly changed their approach and began to compromise TCP port 443, which is much harder for security software to detect as it usually only handles encrypted data.

At least 20 command-and-control servers have been detected since April 2023, indicating that the threat actors behind IcedID are keen to not only disguise their tracks, but also keep security experts guessing. IcedID appears to compromise its victims by carrying out a sustained campaign of data harvesting and using them as a connection point in spamming campaigns, which are used to spread IcedID even further.

Staying Safe from IcedID

The exact point at which this current IcedID campaign infects a host is currently unknown, but earlier variants of IcedID from 2023 used malicious email attachments. Therefore, it’s important for all your PC users to remain vigilant against the threat of infected emails arriving in their inbox. In particular, make sure they look out for the following:

For more ways to secure and optimize your business technology, contact your local IT professionals.

Read More