Retefe (Windows)
Aliases: Tsukuba, Werdlod
- First seen
- 2014-02-01 00:00:00
- Malware type
- credential-stealer, trojan, downloader, dropper
- Family
- Malware family
- Last IoC activity
- 2026-05-11 06:57:22
- Profile updated
- 2026-07-07 14:09:36
Targeted industries: financial-services
Targeted regions: country_code:ch
Context
Retefe is a Windows Banking Trojan that can also download and install additional malware onto the system using Windows PowerShell. It's primary functionality is to assist the attacker with stealing credentials for online banking websites. It is typically targeted against Swiss banks. The malware binary itself is primarily a dropper component for a Javascript file which builds a VBA file which in turn loads multiple tools onto the host including: 7zip and TOR. The VBA installs a new root certificate and then forwards all traffic via TOR to the attacker controlled host in order to effectively MITM TLS traffic.
Reports & references
- govcert.admin.ch — The Retefe Saga (report)
- proofpoint.com — 2019 Return Retefe (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Retefe (report)
- github.com — Retefe (report)
- threatpost.com — 128103 (report)
- researchcenter.paloaltonetworks.com — Retefe Banking Trojan Targets Sweden Switzerland And Japan (report)
- vulnerability.ch — Analysing Retefe With Sysmon And Splunk (report)
- govcert.admin.ch — Reversing Retefe (report)
- github.com — Retefe Unpacker (report)