KrBanker
Aliases: BlackMoon
- First seen
- 2014-01-01 00:00:00
- Malware type
- trojan, credential-stealer
- Family
- Malware family
- Last IoC activity
- 2026-07-19 02:48:49
- Profile updated
- 2026-07-07 15:08:51
Targeted industries: financial-services
Targeted regions: country_code:kr
Context
ThreatPost describes KRBanker (Blackmoon) as a banking Trojan designed to steal user credentials from various South Korean banking institutions. It was discovered in early 2014 and since then has adopted a variety of infection and credential stealing techniques.
Detection coverage
- 2 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Win_Blackmoon (yara-rule)
- MALPEDIA_Win_Krbanker_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Krbanker (report)
- proofpoint.com — Updated Blackmoon Banking Trojan (report)
- zairon.wordpress.com — Trojan Banking 47D18761D46D8E7C4Ad49Cc575B0Acc2Bb3F49Bb56A3D29Fb1Ec600447Cb89A4 (report)
- peppermalware.com — Analysis Of Blackmoon Banking Trojans (report)
- researchcenter.paloaltonetworks.com — Unit42 Krbanker Targets South Korea Through Adware And Exploit Kits 2 (report)
- rapid7.com — Old Blackmoon Trojan New Monetization Approach (report)
- fidelissecurity.com — Blackmoon Banking Trojan New Framework (report)