I noticed that there was no thread in this Forum for the Retefe Banking Trojan, so I created one.
There's an ongoing spam campaign targeting Swiss users which sends Word Documents with embedded LNK files to spread Retefe.
References:
http://www.pwncode.club/2017/09/deep-di ... rojan.html
https://www.proofpoint.com/us/threat-in ... -campaigns
It looks like the new variants of Retefe Banking Trojans are not using the Eternal Blue Exploit once again. Maybe, there are plans to update the exploit or add a new variant? :)
There's an ongoing spam campaign targeting Swiss users which sends Word Documents with embedded LNK files to spread Retefe.
References:
http://www.pwncode.club/2017/09/deep-di ... rojan.html
https://www.proofpoint.com/us/threat-in ... -campaigns
It looks like the new variants of Retefe Banking Trojans are not using the Eternal Blue Exploit once again. Maybe, there are plans to update the exploit or add a new variant? :)