Skip to content

Hide Navigation Hide TOC

feodo (372cdc12-d909-463c-877a-175f97f7abb5)

Unfortunately, it is time to meet 'Feodo'. Since august of this year when FireEye's MPS devices detected this malware in the field, we have been monitoring this banking trojan very closely. In many ways, this malware looks similar to other famous banking trojans like Zbot and SpyEye. Although my analysis says that this malware is not a toolkit and is in the hands of a single criminal group.

Cluster A Galaxy A Cluster B Galaxy B Level
Feodo (66781866-f064-467d-925d-5e5f290352f0) Malpedia feodo (372cdc12-d909-463c-877a-175f97f7abb5) Tool 1