KrBanker

Aliases: BlackMoon

First seen
2014-01-01 00:00:00
Malware type
trojan, credential-stealer
Family
Malware family
Last IoC activity
2026-07-19 02:48:49
Profile updated
2026-07-07 15:08:51

Targeted industries: financial-services

Targeted regions: country_code:kr

Context

ThreatPost describes KRBanker (Blackmoon) as a banking Trojan designed to steal user credentials from various South Korean banking institutions. It was discovered in early 2014 and since then has adopted a variety of infection and credential stealing techniques.

Detection coverage

  • 2 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Win_Blackmoon (yara-rule)
  • MALPEDIA_Win_Krbanker_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Krbanker (report)
  • proofpoint.com — Updated Blackmoon Banking Trojan (report)
  • zairon.wordpress.com — Trojan Banking 47D18761D46D8E7C4Ad49Cc575B0Acc2Bb3F49Bb56A3D29Fb1Ec600447Cb89A4 (report)
  • peppermalware.com — Analysis Of Blackmoon Banking Trojans (report)
  • researchcenter.paloaltonetworks.com — Unit42 Krbanker Targets South Korea Through Adware And Exploit Kits 2 (report)
  • rapid7.com — Old Blackmoon Trojan New Monetization Approach (report)
  • fidelissecurity.com — Blackmoon Banking Trojan New Framework (report)

External references