Chthonic is a Windows banking Trojan in the ZeuS lineage, identified as an evolution of ZeusVM with substantial architectural changes and overlap with techniques associated with Andromeda and KINS. First observed in 2014, it targets online banking and payment systems and has been associated with campaigns against financial institutions across multiple countries, including strong targeting of banks in the UK, Spain, the US, Russia, Japan, and Italy. Chthonic has also appeared in geographically focused criminal campaigns, including activity linked to TA544 in Italy, and has been used in broader malware delivery ecosystems alongside families such as AZORult and Smoke Loader.
The malware uses a modular design. Documented modules support web injection and form grabbing for banking fraud, theft of saved passwords, keylogging, VNC-based remote access, SOCKS proxying, webcam recording, and collection of host information. Its webinject capability has been used to steal credentials, phone numbers, one-time passwords, PINs, and TANs, and in some cases to hide legitimate banking warnings or present spoofed banking content to facilitate fraudulent transactions. Chthonic loaders and modules employ layered encryption and custom loading techniques, including RC4, AES, virtual-machine-based configuration decryption, and direct in-memory loading of non-PE ZeuS-style modules. Anti-analysis checks for debugging, sandboxing, virtualization, and related artifacts have also been reported.
Observed infection vectors include malicious email campaigns carrying crafted Microsoft Office documents exploiting CVE-2014-1761, exploit-kit delivery including RIG, fake browser update chains associated with SocGholish, and secondary delivery by other malware such as Andromeda and Upatre. Chthonic has also been distributed through malicious document builder ecosystems such as Microsoft Word Intruder and ThreadKit. In some campaigns it acted as a downloader for additional payloads, including AZORult.
Chthonic is best understood as a mature crimeware banking platform derived from leaked ZeuS code and adapted for credential theft, fraudulent banking operations, and remote operator access on compromised Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
When sending messages containing an exploit, cybercriminals attached a specially crafted RTF document, designed to exploit the CVE-2014-1761 vulnerability in Microsoft Office products. | Kaspersky Lab products detect the new banking malware as Trojan-Banker.Win32.Chthonic. The Trojan is apparently an evolution of ZeusVM, although it has undergone a number of significant changes.
Edit : 2014-12-21 - Kaspersky named what we were calling Andromedins or AndroKins : Chthonic | The first encounter I had with this CVE in exploit kit, was in the Sweet Orange... already containing CVE-2014-6332... Sweet Orange firing CVE-2014-6332 and DarkShell Call back... Here a more "standard" Sweet Orange : CVE-2014-6332 fired by Sweet Orange - And Betabot call back... Neutrino Firing CVE-2014-6332... Archie... CVE-2014-6332... Flash EK firing CVE-2014-6332... NB : it's in RIG and Angler
However, an exploit for Microsoft Word (CVE-2012-0158), which was first associated with APT activity, found its way into the hands of traditional cybercriminals who began using it in spam campaigns in 2013.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Italy (Active) Italian Panda (Multiple Versions), Chthonic, Smoke Loader, Ursnif (Multiple Affids) Medium Volume Manufacturing and Retail
25 distinct techniques documented for this family, organized by ATT&CK tactic.
The beginning of an infection chain starts with a legitimate website with injected code... The end result looked like the image below... Fake browser update page seen after visiting a legitimate website.
The sample, 94a8b4b22dab4171edde5b1bafbf2f17dbe3c3c4c01335c36ba3b6e5d3635b83, was compiled six days after our Upatre sample and delivered the Chthonic banking trojan via RIG exploit kit.
Specifically, we observed emails with the subject “You’ve got a money request” that came from PayPal. The sender does not appear to be faked: instead, the spam is generated by registering with PayPal (or using stolen accounts) and then using the portal to “request money.”
Chthonic will also create a simple batch file which goes through a loop and will delete the dropper and the batch file once it has installed the payload.
The first encounter I had with this CVE in exploit kit, was in the Sweet Orange... already containing CVE-2014-6332 ... Sweet Orange : The URL pattern are different... CVE-2014-6332 in Sweet Orange 2014-11-19
If the user does click on the Goo.gl link, they are redirected to katyaflash[.]com/pp.php, which downloads an obfuscated JavaScript file named paypalTransactionDetails.jpeg.js to the user’s system. If the user then opens the JavaScript file, it downloads an executable from wasingo[.]info/2/flash.exe.
If the user does click on the Goo.gl link, they are redirected to katyaflash[.]com/pp.php, which downloads an obfuscated JavaScript file named paypalTransactionDetails.jpeg.js to the user’s system.
The attached ZIP file contains a malicious Word document ( 603f1fcb9897e8aaf8becfc6127d40a7, Info.doc ) which, instead of connecting out to a server to download the payload, simply drops a payload contained within the malicious document.
Chthonic will also create a simple batch file which goes through a loop and will delete the dropper and the batch file once it has installed the payload.
The first stage packer is a simple Visual Basic packer that performs basic anti-analysis checks... Once the payload for the second stage packer is decoded and executed, it checks the environment for possible analysis tools. Similar to Andromeda, if any of these checks are successful, the malware enters an infinite sleep loop.
According to the Kaspersky researchers, as a descendant of Zeus, Chthonic has targeted a large number of online-banking systems in efforts to get a hold of and use potential victims’ online banking credentials to stealthily perform financial transactions.
According to analysis by Kaspersky, these modules include the capability to collect system information, extract saved passwords, enable remote access (VNC) and log keystrokes
The initial beacon message includes information about the system and the malware itself.
The first stage packer is a simple Visual Basic packer that performs basic anti-analysis checks... Once the payload for the second stage packer is decoded and executed, it checks the environment for possible analysis tools. Similar to Andromeda, if any of these checks are successful, the malware enters an infinite sleep loop.
According to the Kaspersky researchers, as a descendant of Zeus, Chthonic has targeted a large number of online-banking systems in efforts to get a hold of and use potential victims’ online banking credentials to stealthily perform financial transactions.
Over the last six years there has been an increased shift by malware authors to secure their C&C communications using the SSL/TLS protocol to stymie detection and blend in with normal traffic.
The malware is primarily a downloader that obtains additional modules using HTTP POST requests.
According to analysis by Kaspersky, these modules include the capability to collect system information, extract saved passwords, enable remote access (VNC) and log keystrokes in addition to the ability to turn the compromised host into a proxy server
Upatre is a stage-0 malware, which basically means it’s a downloader. The malware is used to download and install a payload onto the affected system. The payload is retrieved from hardcoded domain(s) and is typically another piece of malware.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The State of SSL/TLS Certificate Usage in Malware C&C Communications AdWind ostap AsyncRAT BazarBackdoor BitRAT Buer Chthonic CloudEyE Cobalt Strike DCRat Dridex FindPOS GootKit Gozi IcedID ISFB Nanocore RAT Orcus RAT PandaBanker Qadars QakBot Quasar RAT Rockloader ServHelper Shifu SManager TorrentLocker TrickBot Vawtrak Zeus Zloader
A Zeus-descended banking trojan evolved from ZeusVM that targets online-banking systems to steal credentials and perform fraudulent financial transactions.
Banking malware mentioned only in passing as part of the Zeus family lineage.
Banking malware mentioned as one of the payloads distributed through fake browser update pages associated with SocGholish.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.