Amavaldo

Description

(ESET) Most Latin American banking trojans we have analyzed connect to the C&C server and stay connected, waiting for whatever commands the server sends. After receiving a command, they execute it and wait for the next one. The commands are probably pushed manually by the attacker. You can think of this approach as a chat room where all the members react to what the admin writes.

Names

Name
Amavaldo

Category

Malware

Type

  • Banking trojan
  • Backdoor
  • Keylogger
  • Info stealer
  • Credential stealer

Information

Other Information

Uuid

f04824f9-64ff-4ac5-94cc-cd3d067abbb1

Last Card Change

2021-04-21