Skip to content
June 23, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Malware
  • Hackers use website of Ukrainian accounting software developer to disseminate a new variant of Zeus Bank Trojan
  • Malware

Hackers use website of Ukrainian accounting software developer to disseminate a new variant of Zeus Bank Trojan

Do Son January 9, 2018 3 minutes read
Add as a preferred
source on Google

According to foreign media reports on January 6, hackers abuse the official website of Ukrainian accounting software developer Crystal Finance Millennium (CFM) to distribute malware and distribute new variants of Zeus Bank Trojans. Cisco Talos said the malware was acquired through a download program attached to spam and has a range of spreads.

The attack occurred before and after the holiday of Independence Day of Ukraine in August 2017, when Ukrainian authorities and enterprises received cyber-attacks alerts from the local security company ISSP. A domain name used to host the malicious software was related to the website of the Ukrainian accounting software developer CFM. Not only that, but the attacker also used the CFM website to spread the PSCrypt ransomware, which was malware targeted at Ukrainian users last year. Fortunately, this attack hacker did not compromise CFM’s update server and did not see the same level of access in earlier Nyetya protocols.

In this attack, the malware-loaded email contains a JavaScript archive that is used as a malware-download program. Once the file is opened, Javascript will be executed and cause the system to retrieve the malware’s playload. After running, the Zeus Bank Trojan virus will infect the system.

Cisco Talos Statistics: Affected by the new variant of Zeus Bank Trojan

Since the source code for Zeus Trojan 2.0.8.9 was leaked in 2011, other threat actors have been inspired by malicious code to incorporate it into several other bank trojans. Researchers found code reuse exists between the malware released this campaign and the leaked version of Zeus source code:

Once executed on the system, the malware performs a number of operations to determine if it is executing in a virtual sandbox environment. If the malware does not detect that it is running in a sandboxed environment, then it takes steps to make it persistent on the infected system. Malware even creates a registry entry on the infected system to ensure that malicious code is executed each time the infected device is restarted. Once the system is infected, malware tries to contact different C & C servers.

The researchers said most malware-infected systems are in Ukraine and the United States, with ISPs of PJSC Ukrtelecom, which are under the jurisdiction of the Ministry of Transport of Ukraine, the worst affected. Impact reached 3115 unique IP addresses, with 11,925,626 beacons showing the scale of the malware.

Researchers say more and more attackers are trying to abuse trusted software makers as a means of gaining a foothold in the target environment. In order to deploy more effective security controls to protect their network environment, attackers are constantly improving their methods of attack.

Source: IBTimes

Related coverage

  • APT organization steals D-Link company digital certificate to sign its malware
  • LockPoS malware use new injection technology to sneaks onto Kernel
  • Hijacking the Hackers: Researchers Sinkhole “KazakRAT” Espionage Campaign
  • Palo Alto Networks Revealed Worldwide Linux XorDDoS Campaign
  • APT-C-60 Targets Japan: New SpyGlace Malware Uses VHDX LNK and GitHub Tasking for Persistent Espionage

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Zeus Bank Trojan

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🔴 Live Critical Threats

  • CVE-2026-12866CVSS 9.8
    All versions of the package expr-eval are vulnerable to Code Execution via...
  • CVE-2026-54352CVSS 9.6
    ## Summary `POST /api/pwa/process-zip` at `packages/server/src/api/routes/static.ts:24` accepts a builder-uploaded `.zip`, extracts it...
  • CVE-2026-48746CVSS 9.1
    vLLM is an inference and serving engine for large language models (LLMs)....
  • CVE-2026-48170CVSS 9.1
    ## Summary `scim-patch` performs prototype pollution when applying a SCIM PATCH operation...
  • CVE-2026-46495
    ## Summary **Description** A Deserialization of Untrusted Data (CWE-502) issue in OpenDJ's...
  • CVE-2026-56348CVSS 9.1
    n8n before 2.20.0 contains a credential exfiltration vulnerability in the POST /rest/dynamic-node-parameters/options...
  • CVE-2026-46488
    ### Summary An authentication bypass vulnerability exists due to improper trust in...
  • CVE-2026-44203CVSS 9.3
    ### Summary The OAuth 2.0 / OpenID Connect authorization endpoint does not...
  • CVE-2026-44179CVSS 9.9
    ### Summary The excerpt-include macro does not properly escape the title of...
  • CVE-2026-10789CVSS 9.6
    A maliciously crafted webpage, when visited by a user with Autodesk Fusion...
Powered by CVE WATCHTOWER

🚨 Active Exploits in the Wild

  • CVE-2026-20230CVSS 8.6
    A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified...
  • CVE-2026-4020CVSS 7.5
    The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and...
  • CVE-2026-10735
    Multiple plugins by ShapedPlugin contain a backdoor in various versions. This makes it possible for unauthenticated attackers to...
  • CVE-2026-20262CVSS 6.5
    A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated,...
  • CVE-2026-54420CVSS 8.5
    LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a...
  • CVE-2026-53435CVSS 8.8
    In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize...
  • CVE-2026-10795CVSS 8.1
    The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions...
  • CVE-2026-11645
    Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker...
  • CVE-2026-50751CVSS 9.3
    A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows...
  • CVE-2026-20245CVSS 7.8
    A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, local...
Powered by CVE Watchtower

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.