Vawtrak, also known as Neverquest and Snifula, is a Windows banking trojan descended from the Gozi lineage and operated as a cybercrime-as-a-service offering. It is primarily associated with theft from online banking users through credential harvesting and web-injection-based fraud, and it has also been described as an information-stealing backdoor with modular functionality. Reported modules and behaviors include credential theft, keylogging, web injects, back-connect capability, and retrieval of additional components or secondary malware. Vawtrak has also been observed using TLS-protected command-and-control communications, including self-signed certificates and certificate-pinning style validation logic.
Vawtrak has been delivered through multiple intrusion chains. Observed distribution methods include exploit-kit delivery, especially via Angler, as well as malspam and phishing campaigns using malicious Microsoft Office documents with macros. It has also appeared as a follow-on payload delivered by malware such as Hancitor, Chanitor, Ruckguv, H1N1 Loader, Bedep, and Pony-related chains. Campaign reporting links Vawtrak to infections targeting financial institutions and customers in multiple regions, including Japan, the United States, Canada, the United Kingdom, and Spain. Japanese banking targets were specifically noted in exploit-kit-driven campaigns.
The malware is strongly associated with financially motivated operations. It has been tied to large banking-trojan ecosystems alongside families such as Gozi, Tinba, Dridex, Panda Banker, Qadars, Ramnit, and Shifu. Technical reporting has also noted code or tradecraft overlap with other banking malware, and later malware such as Karius reused techniques previously seen in Vawtrak. Law-enforcement action against Stanislav Vitaliyevich Lisov was publicly linked to creation and operation of Vawtrak, after which activity reportedly declined.
Vawtrak is best characterized as a modular banking trojan for Windows that combines credential theft, browser/session manipulation, and downloader-style post-compromise extensibility to support online banking fraud and related financially motivated intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Some of these include: Exploitation of CVE-2016-0167 a Microsoft Windows Privilege Escalation vulnerability to gain SYSTEM level privileges. The second stage injector contains two exploits for CVE-2016-0167 (x86/x64)... At the time of compilation, patches were not yet available for this vulnerability. | Additionally, we identified a version of Vawtrak which contains an earlier version of the exploit dating back to November 2015, according to the compilation time stamp.
Neutrino firing his bundle of Sploit : 2015-02-06 Note: in this pass the Vawtrak payload is most probably CVE-2014-6332 load | note that CVE-2014-6332 is in RIG as well ... Note: in this pass the Vawtrak payload is most probably CVE-2014-6332 load
CVE-2015-0311 (Flash up to 16.0.0.287) integrating Exploit Kits Patched with Flash 16.0.0.296 ... first seen exploited by Angler EK ... soon after used in standalone mode in huge malvert campaign ... integrated today in RIG ... Fiesta ... Nuclear Pack ... Sweet Orange ... Neutrino ... Magnitude
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Angler infecting a VM and integrating it into an instance of Bedep botnet
Proofpoint researchers have also observed this infection behavior delivered by an Angler EK → Bedep → Vawtrak infection ... and Angler EK → Bedep (bypassing Vawtrak).
Many fileless malware embed malicious PowerShell scripts whose commands are often the ones responsible for downloading and launching or executing the payload.
Initial infections were of random computers via indiscriminate spam campaigns that included malicious Word macros.
Both banking Trojans are using the same dynamic injects system that allows them to manipulate a financial institution’s website content. This means that the two banking Trojans use the same JavaScript code for stealing login credentials, PINs, one-time-passwords, etc.
CVE-2015-0311 has been first seen exploited by Angler EK ... soon after used in "standalone" mode in huge malvert campaign ... CVE-2015-0311 has been integrated today in RIG ... Fiesta successfully exploit Windows XP IE8 Flash 16.0.0.257 using CVE-2015-0311 ... Nuclear Pack successfully exploit ... using CVE-2015-0311 ... Sweet Orange firing exploit for CVE-2015-0311 ... Neutrino firing his bundle of Sploit ... Magnitude - CVE-2015-0311 exploited successfully
This is the only C2 response that is unencrypted, all other responses are encrypted using RC4. Some responses are, like the configs, also compressed using LZMAT.
The nature of malware communications with its C&C server(s) has advanced over time, from using plain non-encrypted channels to using custom and standard symmetric ... and asymmetric ... encryption algorithms and protocols (SSL/TLS) to hinder network inspection of such malicious traffic.
It then waits for a few seconds before deleting the original file... The Vawtrak dropper Trojan then deletes itself from the target system.
If no debugger is found, the binary then unpacks an embedded DLL and writes it to disk.
Dubbed ‘Karius’, the Trojan aims to carry out web injects to add additional fields into a bank’s legitimate login page and send the inputted information to the attacker.
They’re still gathering any data that they deem interesting such as credentials for online services... The other two configs are used to control how the bot will interact with the targeted entities, such as redirecting and modifying web traffic related to for example internet banking and/or email providers, for the purpose of harvesting credentials and account information.
A system infected with Avalanche-associated malware may be subject to malicious activity including the theft of user credentials and other sensitive data, such as banking and credit card information.
Dubbed ‘Karius’, the Trojan aims to carry out web injects to add additional fields into a bank’s legitimate login page and send the inputted information to the attacker.
They’re still gathering any data that they deem interesting such as credentials for online services... The other two configs are used to control how the bot will interact with the targeted entities, such as redirecting and modifying web traffic related to for example internet banking and/or email providers, for the purpose of harvesting credentials and account information.
The other two configs are used to control how the bot will interact with the targeted entities, such as redirecting and modifying web traffic related to for example internet banking and/or email providers, for the purpose of harvesting credentials and account information.
Moreover, the adoption of SSL/TLS in malware is not restricted to the HTTPS protocol; other protocols, including SMTP and custom TCP protocols, were also found using SSL/TLS. | Over the last six years there has been an increased shift by malware authors to secure their C&C communications using the SSL/TLS protocol to stymie detection and blend in with normal traffic.
Before this update, the Hancitor command-and-control (C&C) check-in ... used a pipe-separated POST data format... The updated Hancitor submits similar information to the C&C, but in a different format.
At this point, the Hancitor downloader has been fully loaded on the victim’s machine, where it will proceed to perform additional malicious activities.
What made the ’Avalanche’ infrastructure special was the use of the so-called double fast flux technique. The complex setup of the Avalanche network was popular amongst cybercriminals, because of the double fast flux technique offering enhanced resilience to takedowns and law enforcement action.
65 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
39 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The State of SSL/TLS Certificate Usage in Malware C&C Communications AdWind ostap AsyncRAT BazarBackdoor BitRAT Buer Chthonic CloudEyE Cobalt Strike DCRat Dridex FindPOS GootKit Gozi IcedID ISFB Nanocore RAT Orcus RAT PandaBanker Qadars QakBot Quasar RAT Rockloader ServHelper Shifu SManager TorrentLocker TrickBot Vawtrak Zeus Zloader
An information-stealing backdoor trojan, also known as NeverQuest and Snifula, primarily used to target online banking accounts. In this case, Chanitor downloads and executes a dropper that unpacks and installs a Vawtrak DLL for persistence.
PC banking trojan listed among malware actively used to attack companies.
A later Gozi evolution developed by the Kuzmin Gang from Gozi v1 into Gozi v2/Prinimalka, also known as Vawtrak.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.