Neverquest, also known as Vawtrak and internally referred to by its operators as Catch, is a banking trojan focused on theft from online financial accounts. It targeted financial institutions worldwide and was used to steal banking credentials, account information, and related authentication data. The malware supported web-based fraud through modification of banking webpages and injection of rogue forms designed to capture usernames, passwords, and security-question responses. It also provided remote access to compromised systems through VNC functionality, enabling operators to interact with victim machines and conduct fraudulent banking sessions.
Neverquest spread through multiple channels including email, social media, and file-transfer-based distribution. Its operational model supported large-scale credential harvesting and monetization of stolen financial data. Reporting on law-enforcement action linked the malware to Stanislav Lisov, who was arrested on suspicion of creating and operating the trojan. Neverquest has also been discussed in relation to the broader Eastern European banking-trojan ecosystem, including links to Vawtrak branding and historical overlap with crimeware operations associated with Gozi-derived development.
The malware is notable both as a standalone banking threat and for its place in the evolution of banking trojans after source-code leakage in the cybercrime ecosystem. Available reporting indicates that leaked code from related malware families contributed to later strains including Neverquest, while subsequent research connected operational elements of the Neverquest/Vawtrak ecosystem to later banking malware such as Bokbot. Neverquest is therefore significant as both a credential-theft platform and a node in the lineage of financially motivated malware used against banks and their customers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
They’re still gathering any data that they deem interesting such as credentials for online services... The other two configs are used to control how the bot will interact with the targeted entities, such as redirecting and modifying web traffic related to for example internet banking and/or email providers, for the purpose of harvesting credentials and account information.
They’re still gathering any data that they deem interesting such as credentials for online services... The other two configs are used to control how the bot will interact with the targeted entities, such as redirecting and modifying web traffic related to for example internet banking and/or email providers, for the purpose of harvesting credentials and account information.
The other two configs are used to control how the bot will interact with the targeted entities, such as redirecting and modifying web traffic related to for example internet banking and/or email providers, for the purpose of harvesting credentials and account information.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of the banking trojan strains tied to leaked Gozi source code.
Long-running banking trojan/botnet operation tied to fraud and credential theft, including form grabbing, web injects, and rented/private botnet operations. The report presents it as the predecessor and likely lineage connection for Bokbot.
Banking trojan that steals banking data and login credentials. It spreads via social media, email, and file transfer protocols; can modify banking website content, inject rogue forms to harvest credentials, and provides remote control of compromised systems through a VNC server so attackers can access victims’ online banking accounts and steal funds.
Mentioned as a potentially related banking trojan family; the paper cites overlap in admin panels and JavaScript/webinject tooling that may indicate collaboration with Pinkslipbot operators.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.