Chthonic

Aliases: AndroKINS

First seen
2014-12-01 00:00:00
Malware type
trojan, credential-stealer
Family
Malware family
Last IoC activity
2026-07-19 21:56:59
Profile updated
2026-07-07 14:31:53

Targeted industries: financial-services

Targeted regions: country_code:ru country_code:ua country_code:gb

Context

Chthonic is a banking trojan malware that primarily targets financial institutions. It is known for its credential-stealing capabilities and has been linked to attacks mostly in Russia, Ukraine, and the United Kingdom.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Chthonic_Auto (yara-rule)

Reports & references

  • Trend Micro — Ssl Tls Technical Brief (report)
  • proofpoint.com — Threat Actors Using Legitimate Paypal Accounts To Distribute Chthonic Banking Trojan (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Chthonic (report)
  • Kaspersky — 68176 (report)
  • bartblaze.blogspot.com — Crystal Finance Millennium Used To (report)

External references