BlackMoon, also known as KRBanker, is a Windows banking Trojan first observed targeting South Korean financial institutions in 2015. Its primary credential-theft mechanism is pharming: it modifies local name-resolution or proxy auto-configuration settings to redirect visits to targeted banking websites through attacker-controlled phishing workflows that solicit online-banking credentials and other personal information. It has also searched for and exfiltrated South Korean NPKI certificate material. BlackMoon has used multi-stage downloaders, configuration retrieval, DLL execution, process injection, anti-debugging, and persistence mechanisms including registry autoruns and malicious services. Early distribution included drive-by downloads and exploit kits. Later campaigns targeting businesses in the United States and Canada used BlackMoon-associated components for durable access, defense evasion, network scanning and propagation using EternalBlue and DoublePulsar tooling, and deployment of cryptomining and traffic-sharing payloads. A 2025 espionage campaign against Indian users used a BlackMoon variant in tax-themed phishing chains to manipulate Avast exclusions and support deployment of a repurposed remote-management product for monitoring and data theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
malicious JavaScript through compromised web sites or advertisements led to the EK that exploited Adobe Flash vulnerabilities CVE-2014-0569 or CVE-2015-3133. We confirmed that final payload in both cases was KRBanker.
malicious JavaScript through compromised web sites or advertisements led to the EK that exploited Adobe Flash vulnerabilities CVE-2014-0569 or CVE-2015-3133. We confirmed that final payload in both cases was KRBanker.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Some aspects of the campaign were previously highlighted by eSentire in January 2026, with the attacks using tax-themed lures to target Indian users with the Blackmoon malware.
Some aspects of the campaign were previously highlighted by eSentire in January 2026, with the attacks using tax-themed lures to target Indian users with the Blackmoon malware.
Some aspects of the campaign were previously highlighted by eSentire in January 2026, with the attacks using tax-themed lures to target Indian users with the Blackmoon malware.
Some aspects of the campaign were previously highlighted by eSentire in January 2026, with the attacks using tax-themed lures to target Indian users with the Blackmoon malware.
Some aspects of the campaign were previously highlighted by eSentire in January 2026, with the attacks using tax-themed lures to target Indian users with the Blackmoon malware.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
malicious JavaScript through compromised web sites or advertisements led to the EK that exploited Adobe Flash vulnerabilities CVE-2014-0569 or CVE-2015-3133. We confirmed that final payload in both cases was KRBanker. | Our analysis shows that KRBanker has been distributed through web exploit kits (EK) and a malicious Adware campaign.
Reportedly distributed through adware and exploit kits, we can see below that the BlackMoon perpetrators are consistently able to infect users, averaging 443 infections per day
BlackMoon is a banking Trojan that installs a proxy auto-config file (PAC) on an infected system in order to redirect users’ browsers to phishing pages related to South Korean banks.
creates the following registry entry. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoConfigURL = http://127.0.0.1:[random]/[random]
Blackmoon drops a dll into C:\Windows\Logs folder named RunDllExe.dll and implements a Port Monitor persistence technique... it calls AddMonitor API to immediately execute RunDllExe.dll and sets a driver value in HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\RunDllExe registry key to the malicious dll path.
KRBanker uses Process Hollowing to execute its main code in a clean (non-suspicious) executable.
Blackmoon drops a dll into C:\Windows\Logs folder named RunDllExe.dll and implements a Port Monitor persistence technique... it calls AddMonitor API to immediately execute RunDllExe.dll and sets a driver value in HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\RunDllExe registry key to the malicious dll path.
It then registers the compromised system with the C2 server by sending the following HTTP GET request
The latest version of the threat employs Proxy Auto-Config(PAC)... The adversaries abuse this feature for Pharming. To configure this, the Trojan starts a local proxy server
Researchers at ALYac had reported previously, on KRBanker employing hosts file modification and local DNS proxy techniques to redirect HTTP traffic.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Banking malware distributed via fake tax-themed phishing campaigns targeting Indian taxpayers and businesses.
Remote-access trojan mentioned only for comparison with other LetsVPN-themed malware operations.
Malware used in tax-themed lure campaigns targeting Indian users, as referenced in prior reporting tied to Silver Fox activity.
Multi-stage backdoor delivered via phishing emails impersonating India's Income Tax Department; suspected espionage targeting Indian users.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.