Shifu
- First seen
- 2015-06-15 00:00:00
- Malware type
- trojan, credential-stealer
- Family
- Malware family
- Last IoC activity
- 2026-06-27 03:43:36
- Profile updated
- 2026-07-07 12:54:05
Targeted industries: financial-services
Targeted regions: country_code:jp
Context
Shifu was originally discovered by Trusteer security researchers (Ilya Kolmanovich, Denis Laskov) in the middle of 2015. It is a banking trojan mostly focusing on Japanese banks and has rich features for remote data extraction and control.
Detection coverage
- 2 YARA rules
Detection rules
- TRELLIX_ARC_Shifu (yara-rule)
- MALPEDIA_Win_Shifu_Auto (yara-rule)
Reports & references
- pwc.co.uk — Cyber Threats 2019 Retrospect (report)
- blog.intel471.com — A Brief History Of Ta505 (report)
- intel471.com — A Brief History Of Ta505 (report)
- Trend Micro — Ssl Tls Technical Brief (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Shifu (report)
- virusbulletin.com — Shifu Rise Self Destructive Banking Trojan (report)
- researchcenter.paloaltonetworks.com — Unit42 2016 Updates Shifu Banking Trojan (report)
- securityintelligence.com — Shifu Masterful New Banking Trojan Is Attacking 14 Japanese Banks (report)