Shifu

First seen
2015-06-15 00:00:00
Malware type
trojan, credential-stealer
Family
Malware family
Last IoC activity
2026-06-27 03:43:36
Profile updated
2026-07-07 12:54:05

Targeted industries: financial-services

Targeted regions: country_code:jp

Context

Shifu was originally discovered by Trusteer security researchers (Ilya Kolmanovich, Denis Laskov) in the middle of 2015. It is a banking trojan mostly focusing on Japanese banks and has rich features for remote data extraction and control.

Detection coverage

  • 2 YARA rules

Detection rules

  • TRELLIX_ARC_Shifu (yara-rule)
  • MALPEDIA_Win_Shifu_Auto (yara-rule)

Reports & references

  • pwc.co.uk — Cyber Threats 2019 Retrospect (report)
  • blog.intel471.com — A Brief History Of Ta505 (report)
  • intel471.com — A Brief History Of Ta505 (report)
  • Trend Micro — Ssl Tls Technical Brief (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Shifu (report)
  • virusbulletin.com — Shifu Rise Self Destructive Banking Trojan (report)
  • researchcenter.paloaltonetworks.com — Unit42 2016 Updates Shifu Banking Trojan (report)
  • securityintelligence.com — Shifu Masterful New Banking Trojan Is Attacking 14 Japanese Banks (report)

External references